This is the syntax and behaviour reference for the Studio engines that model how work, material, risk and control logic move through a real operation. It covers lean and flow (value stream maps, cumulative flow, queueing networks, spaghetti diagrams, swimlanes, Kanban boards and service blueprints), quality and improvement (SIPOC, control charts, Pareto charts, fishbones and design structure matrices), risk, safety and reliability (fault trees, bowties, reliability block diagrams and attack trees), and automation and process engineering (ladder logic, GRAFCET and P&ID). Most of these engines do more than draw. A value stream map works out its own lead time, a control chart computes its own limits, a fault tree computes its own top-event probability, and a ladder diagram is solved for one scan. For each engine you will find the statements it reads, every keyword and alias, the defaults it assumes, what it computes, what it flags, its size limits and the templates you can start from. For a guided tour of the analysis with worked examples, read Flow-systems analysis in Studio alongside this page.
At a glance
| Engine | Engine id | Studio library group | What it computes or checks | Reference |
|---|---|---|---|---|
| Value stream map | valuestream | Flow systems | Lead time, value-added time, flow efficiency, rolled throughput yield, takt, steps over takt, the constraint | /docs/engines/valuestream |
| Flow metrics (CFD) | cfd | Flow systems | WIP, throughput, cycle and lead time by Little's Law, residence per stage, flow efficiency, delivery trend, runaway queues | /docs/engines/cfd |
| Queueing network | queueing | Flow systems | Traffic equations, utilisation, waiting probability, queue length, waiting and response time, blocking, the bottleneck and the servers needed | /docs/engines/queueing |
| Spaghetti diagram | spaghetti | Flow systems | Travel per actor and in total, legs, longest leg, busiest link, visits, crossings, before-and-after savings | /docs/engines/spaghetti |
| Swimlane process | swimlane | Flow & UML | Column layout by longest path; checks decisions, exits, reachability and lanes | /docs/engines/swimlane |
| Kanban board | kanban | Flow & UML | Card counts against WIP limits; reports lines it could not place | /docs/engines/kanban |
| Service Blueprint | serviceblueprint | Flow & UML | Five-lane blueprint; reports unknown keys, repeated and empty lanes | /docs/engines/serviceblueprint |
| SIPOC | sipoc | Flow systems | Column counts, requirement gaps and coverage, scope check, metric variance | /docs/engines/sipoc |
| Control chart (SPC) | spc | Quality & control | Centre line and control limits, all eight Nelson rules, Cp, Cpk, Pp, Ppk and expected PPM | /docs/engines/spc |
| Pareto chart | pareto | Quality & control | Shares, cumulative percentage, the vital few, the Pareto ratio sentence, period-on-period movement | /docs/engines/pareto |
| Fishbone (Ishikawa) | fishbone | Research & analysis | Layout of categories and causes; checks for missing problem, empty ribs and repeats | /docs/engines/fishbone |
| Design structure matrix | dsm | Flow systems | Cycles, partitioned order, iteration blocks, feedback marks before and after | /docs/engines/dsm |
| Fault tree (FTA) | faulttree | Risk & reliability | Exact top-event probability, rare-event approximation, minimal cut sets, single points of failure, Birnbaum, Fussell–Vesely and criticality importance | /docs/engines/faulttree |
| Bowtie risk | bowtie | Risk & reliability | Residual threat and top-event frequency, consequence risk, inherent and residual risk, risk reduction, barrier criticality | /docs/engines/bowtie |
| Reliability block diagram | rbd | Risk & reliability | System reliability, unreliability, MTTF, availability, Birnbaum importance, the weakest link, idle redundancy | /docs/engines/rbd |
| Attack tree (cybersec) | attacktree | Risk & reliability | Cost roll-up through AND and OR nodes; reports broken parent links | /docs/engines/attacktree |
| Ladder logic (PLC) | ladder | Quality & control | One scan solved top to bottom; duplicate destinations, outputs never energised, tags read but never written, rungs with no output | /docs/engines/ladder |
| GRAFCET / SFC | grafcet | Quality & control | Alternation, initial steps, reachability, dead ends, AND balance, receptivities, duplicate step numbers | /docs/engines/grafcet |
| P&ID (chemical eng) | pid | Research & analysis | Equipment, ISA-style instrument balloons and process lines; reports unknown endpoints and overlaps | /docs/engines/pid |
Every engine on this page is part of the Studio's engine library and works on every plan, including Free, with no cap on how much you draw. (Free keeps three saved figures per studio; see Plans and what they include.) They all render inside flowss itself, with no outside service, so they work offline, your source never leaves flowss to be drawn, and the render API can draw them on a server. Every computation and every check on this page runs without AI. Only the optional AI features around them (Photo → Engine, AI conversion, Ask the flowss Studio Agent… edits and the flowss Studio Agent) need AI on your plan: your own key from Starter, hosted AI points from Plus. See AI points and limits.
Opening these engines
You can open any engine on this page in four ways.
- From the engine library. Click Engines & templates at the top of the Studio's tool rail, or click the engine name at the top of the code sheet. On the Engines tab, open the group named in the table above (Flow systems, Risk & reliability, Quality & control, Flow & UML or Research & analysis) and click the engine's row.
- By searching. The library's search box ("Search engines — name, or what you're drawing…") matches names and ids, what you are drawing and the tool you are replacing. Try
takt,control chart,fault tree,Minitab,BowTieXPorPLC. - From a link.
/studio?engine=valuestreamopens the Studio with that engine selected, and/studio?template=<template id>opens one template. Every engine's reference page at /docs/engines/ followed by its id has an Open in button and sample templates. - From a template. Press
/in the Studio to open the library on the Templates tab with its search box ready, or browse the template gallery.
Warning: Clicking an engine row replaces the current figure's source with that engine's starter template. It does not convert your diagram.⌘Zbrings the previous source back. To keep your current figure, start a New figure (⌥⌘N) first and pick the engine there. See Choosing an engine.
If you have a photograph of a whiteboard value stream map, a printed ladder diagram, a hand-drawn fault tree or a control chart taped to a machine, Photo → Engine (⋮ → Import, Plus and above) can read it into the matching engine. See Importing and converting.
What these engines have in common
Writing the source
All of these engines read plain text, one statement per line. They are forgiving by design: a half-typed line never blanks the canvas. Lines the engine cannot read are skipped and, in every engine on this page, reported rather than dropped in silence.
| Convention | Applies to |
|---|---|
# or // starts a comment anywhere on a line, outside double quotes | Value stream, queueing, spaghetti, SIPOC, SPC, Pareto, fault tree, bowtie, RBD, ladder, GRAFCET |
# or // starts a comment at the start of a line, or after a space later in the line | CFD (text inside double quotes is protected) and DSM (it is not, so keep # out of DSM names). This is what lets names such as C# and http://svc survive |
# or // starts a comment only at the start of a line | Swimlane, Kanban, Fishbone, Attack tree, P&ID |
# at the start of a line is a comment | Service Blueprint. A line starting // is reported as not read |
| Keywords are case-insensitive | All |
| Quote a name that contains spaces, punctuation or a keyword | All. Double quotes work everywhere; several engines also accept single quotes |
| Blank lines and indentation are decoration | All except the ladder branch block, where indentation marks the legs |
Tip: In the engines that only accept whole-line comments, a trailing // note after a statement becomes part of that statement. Put comments on a line of their own.
Units and numbers
The quantitative engines read units the way you would say them.
| Engine | Durations | A bare number means | Percentages |
|---|---|---|---|
| Value stream map | ms, s, m, h, d, w and their long forms, or compound 1h30m | Seconds | 92%, 0.92 and 92 are the same |
| Queueing network | 250ms, 30s, 8m, 2.5h, 1d, 1w, 1shift (8 hours), compound 1h30m | Seconds for a duration, per hour for a rate | 85%, 0.85 or 85 |
| Fault tree | s, min, h, d, w, mo, y | Hours for a duration, a probability for an event value | Not used |
| Reliability block diagram | s, min, h, d, w, mo, y (18 months, 2.5 y) | Hours | Not used |
| Bowtie | Not used | The statement's natural quantity | 0.8, 80% or 80 |
| CFD | Dates YYYY-MM-DD or YYYY/MM/DD | A cumulative count | Not used |
Defaults are stated, never hidden
Where an engine assumes a value you did not write, it says so on the figure. For example, a fault tree prints its mission time as "8760 h (default)" when you gave none, a bowtie lists every assumed likelihood, severity and effectiveness in its findings, and a queueing network notes when it is sizing servers against the default 85% target.
How findings are graded
Each engine's own checks report findings at one of five levels. This page uses the same five words in each engine's findings table.
| Level | Meaning | Affects readiness |
|---|---|---|
| Error | Two statements that cannot both be true of one document, or a line that was not read and so is in no total | Yes |
| Warning | Probably not what you meant | Yes |
| Gap | The engine could not decide, for example because a size limit was reached. Never your mistake, and never silence | Yes |
| Info | A fact worth stating that is nobody's defect, such as the study's own result | No |
| OK | A check that ran and found nothing | No |
Every engine on this page has its checks wired into the readiness reading in the Document status popover beside the document title (click the status glyph, or press ⇧⌘M). Errors and warnings count against the figure and gaps are recorded as things that could not be checked, so a fault tree with a cyclic gate or a GRAFCET chart whose steps do not alternate cannot read as finished, however tidy it looks. See The Studio editor.
Note: A low flow efficiency, a step over takt, an out-of-control chart, a large walking distance or a single point of failure is never reported as a defect. These are the results the figure exists to show. The checks are mostly about whether the engine read your document completely and whether its statements agree with each other. A few design problems are raised on purpose: a queueing station at or above 100% utilisation has no steady state, so no queue length or waiting time exists for it, and the engine reports that as an Error rather than print numbers that are not answers; a queueing station over its target, a bowtie path with fewer than two barriers or a barrier that changes nothing, and RBD redundancy that buys almost nothing are Warnings.
When a document is too big
Swimlane, Pareto and GRAFCET read lines of up to 2,000 characters, as do Petri nets, the causal DAG and the quadrant matrix. A longer line is not read, and the figure says so by line number, for example "Line 4 was not read — it is 2,431 characters long, and this engine reads lines of up to 2,000 — split it into shorter lines".
Each engine caps the size of what it analyses, listed in Limits at a glance. When a cap is reached the engine keeps drawing what it read, says how much it did not read, and withholds any verdict that would be a claim about the whole: a value stream shows "Flow efficiency (withheld)", a fault tree shows "Top event probability (withheld)", a queueing network names no bottleneck, and sums such as lead time are shown with "≥" because they are floors. If the cut fell before anything drawable, the figure says "…is empty because the document was not read to the end" rather than showing an empty-document hint.
Where results appear
Results are part of the figure: a strip of metric tiles, a findings or notes strip, and marks on the drawing itself (a red step, a bottleneck badge, a highlighted cut set). Exports carry them, so a reviewer sees what you saw. Exports are covered in Exporting your work.
Lean and flow
Value stream map
A lean value stream map whose totals are derived from its steps, so the picture and its numbers cannot drift apart.
title "ED patient flow — current state"
supplier "Walk-ins + ambulance"
customer "Discharged patients" demand: 320/day
available 24h/day
control "Bed-board / EPR"
process Triage { ct: 6m; co: 0; uptime: 98%; operators: 2; shifts: 3 }
wait 22m
process "Doctor assessment" { ct: 18m; uptime: 92%; operators: 4; fpy: 88% }
inventory 12 patients
process Imaging { ct: 35m; uptime: 80%; operators: 3 }
info "Bed requests" from Triage to control electronic
info "Ward assignment" from control to customer manual
Statements
| Statement | Also accepted | What it does |
|---|---|---|
title "…" | title: … | The figure's title. The first one wins |
process NAME { key: value; … } | step, operation, op, activity, or just NAME { … } | A value-adding step. The data box may span several lines, with ; optional between entries |
wait 22m | delay, queue, lag | Non-value-added time between steps |
inventory 12 patients | inv, stock, buffer, wip, backlog | A queue written as a count. Converted to time as count × takt when takt is known. inventory 40 orders 2h pins the time explicitly |
supplier "…" | vendor | The supplier box in the top band |
customer "…" demand: 320/day | client | The customer box. demand: feeds takt |
control "…" | production control, planning, scheduling | The production-control box |
demand 320/day | demand 320 per day | Customer demand on its own line. A number with no period is read per day |
available 24h/day | available time | Work time per demand period. The period after / or per is documentation |
takt 4.5m | takt time | Declares takt outright, overriding the derived value |
info "label" from X to Y | information, signal | An information arrow across the top band |
Information-flow endpoints are supplier, customer, control or a process name (matched without regard to case, and by prefix). The arrow is dashed when the line contains electronic, edi, digital, system or automatic, and solid otherwise (manual and paper are accepted as documentation).
Data-box keys
| Key | Aliases | Value | Meaning |
|---|---|---|---|
ct | c/t, cycle, cycle time, cycletime, time, vat, va | Duration | Cycle time, the step's value-added time |
co | c/o, changeover, changeover time, setup, setup time | Duration | Changeover. co: 0 is a real statement, not a blank |
uptime | availability, avail, oee, up | Percentage | Share of time the step is available |
operators | operator, ops, people, staff, headcount, fte | Count | Parallel operators |
shifts | shift | Count | Shifts worked |
fpy | yield, first pass yield, first-pass yield, quality, ftr | Percentage | First-pass yield |
batch | batch size, lot, lot size | Count | Batch size |
scrap | defects, reject, rework | Percentage | Scrap rate |
Entries may be written key: value, key = value or key value. A key the engine does not model, such as wip: 40, is still shown as an extra row in the data box rather than dropped (up to six extra keys per box).
What it computes
| Tile | How it is computed |
|---|---|
| Lead time | Sum of all cycle times plus all waits and converted inventories |
| Value-added time | Sum of cycle times |
| Flow efficiency | Value-added time ÷ lead time. Green at 20% or more, amber from 5%, red below 5% |
| Process steps | Number of process boxes |
| Rolled throughput yield | Product of first-pass yields; steps without fpy count as 100%. Shown only when some step declares a yield. Green at 90% or more |
| Takt or Takt (derived) | As declared, or available time ÷ demand |
| Steps over takt | Steps whose effective cycle time exceeds takt. Reads "none" when every step keeps up |
| Constraint (eff. C/T) | The step with the largest effective cycle time |
Effective cycle time is cycle time ÷ uptime ÷ operators. Downtime stretches the interval between finished units and parallel operators divide it, so a four-doctor room with an 18-minute consultation is not flagged against a 4.5-minute takt. Without takt (no takt line, and not both demand and available), the takt tiles are simply left out, and a count-only inventory contributes nothing to lead time; the figure shows the raw count instead.
The drawing shows the supplier and customer band with the information arrows, the process boxes with data boxes beneath (up to ten rows each), inventory triangles between steps, and the sawtooth timeline ladder along the bottom, with waits on the upper steps and value-added time on the lower ones.
What it checks
Every line that matches no statement is an Error, because this engine has no catch-all: a mistyped delya 3600 would otherwise take its wait out of the lead time, demnd 400 would leave the map with no takt, and procss "Weld" ct 90 would remove a box and its cycle time from every sum. Up to six such lines are listed one by one, then "…and N further lines." When a size limit is reached, a Gap says so, sums are shown as floors ("Lead time (partial)" with "≥") and the ratios are withheld ("Flow efficiency (withheld)", "Constraint (withheld)").
Note: The document check currently reads only lines that start with a statement keyword. A step written as a bareTriage { ct: 6m }without theprocesskeyword, and the continuation lines of a data box spread over several lines, are drawn and counted correctly on the map but are reported as lines not read in Document status. To keep the status clean, start every step withprocessand keep each data box on one line.
Templates: Hospital Blood Transfusion, Vaccine Fill-Finish Suite, Adult Passport Renewal, Emergency Department, Automotive Door Line, Deployment Pipeline, Mortgage Approval, Restaurant Kitchen Line, Warehouse Fulfilment, Motor Insurance Claims, Semiconductor Fab Module, Speciality Coffee Roastery and Postgraduate Admissions.
Flow metrics (CFD)
A cumulative flow diagram with the flow metrics derived from the same numbers.
title "Platform team — Q3"
unit stories
stages: Backlog*, Ready*, In progress, Review*, Done
commit Ready
wip-limit "In progress" 8
2024-07-01 | 148, 26, 8, 4, 0
2024-07-08 | 156, 34, 18, 13, 9
2024-07-15 | 165, 44, 29, 23, 19
Statements
| Statement | Also accepted | What it does |
|---|---|---|
title "…" | Title. Read only before the first data row | |
unit stories | units | What one count is. Default items |
stages: A, B, C | stage: (the colon is required) | The workflow from left to right. The last stage is "done". A second stages: line is ignored and reported |
commit Ready | commitment, commit point, commitment point | The commitment point. Work before it counts as backlog, not WIP. Defaults to the first stage. Only the first commit line is used |
wip-limit "Stage" 8 | wip limit, wiplimit, wip_limit, wip-limits, limit, limits; : or = before the number also work | A dashed WIP-limit line on that band, flagged when exceeded. Up to eight limits. The stage name is matched without regard to case; a limit whose name matches no stage is currently ignored without a finding, so check the spelling if no dashed line appears |
A data row, such as 2024-07-01, 148, 26, 8 | A pipe character between the date and the counts, as in the example above | One cumulative count per stage |
A trailing * on a stage name, or (queue), (queued), (wait), (waiting) or (q), marks it as a waiting stage. Without at least one waiting stage, flow efficiency reads "n/a" with the caption "mark queue stages with *", rather than being guessed.
Data rows hold, for each stage, how many items had entered that stage by that date. Dates may use - or /. Rows need not be evenly spaced: the x axis is a real date axis and per-day rates use the actual elapsed days. Rows out of date order are sorted. A row label that is not a date is allowed when you use the pipe (for example Sprint 1 | 40, 12, 3); the chart then works in periods rather than days. Numbers may contain _ separators.
What it computes
| Tile | Meaning |
|---|---|
| WIP | Items between the commitment point and done. Caption "committed at Ready" or "arrivals − departures" |
| Throughput | Items finished over the window, per week and per day (or per period when rows are not dated) |
| Cycle time ≈ | Little's Law: WIP ÷ throughput. Approximate, because Little's Law holds for averages of a stable system |
| Lead time ≈ | All items in the system, including backlog, ÷ throughput |
| Flow efficiency | The share of committed WIP in active rather than waiting stages. Amber below 40% |
| Delivery trend | Delivery rate in the second half of the window against the first, per day. "steady" within ±10%, otherwise "accelerating" or "slowing" |
A table beneath the chart has one row per stage, with the columns Stage, Type ("active", "waiting" or "done"), WIP (in your unit), Limit ("—" when none is declared) and Time (in days, or periods when rows are not dated). Time is the stage's residence time, its current WIP ÷ throughput; over the committed stages these add up to the cycle time. A WIP figure over its limit is shown in bold in the warning colour.
Warnings and notes
Up to six warnings and five notes are printed under the chart.
| Message | Meaning |
|---|---|
| "Queue growth: Review widened for 4 straight periods (… → …, +12 stories)" | A waiting band grew for three or more consecutive periods: arrivals have outrun service. "WIP growth" is the same for an active band |
| "In progress holds 11 stories against a WIP limit of 8" | The band's current WIP exceeds its declared limit |
| "Arrivals outran deliveries by 30 stories across the window" | More arrived than finished |
| "Rows were out of date order and have been sorted" | Rows were reordered |
| "3 values raised — a cumulative count cannot fall" | A count dipped and was raised to the previous row's value |
| "2 values capped — a stage cannot receive more than the one before it" | A downstream count overtook its upstream one |
| "No stages: line — assumed 4 stages ending in Done" | Rows arrived without a stages: line |
| "Commit on the terminal stage Done would leave no WIP — measuring from Backlog" | The commitment point named the last stage |
| "Unknown commit stage "Redy" — measuring from Backlog" | The commitment point named no stage |
The chart needs at least two stages and one data row; until then it shows a syntax hint headed "Cumulative flow diagram".
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Value not read | Error | A non-numeric token among a row's counts. The counts after it shift into the wrong stages |
| Line not read | Error | A line that is neither a directive nor a data row |
| Stages undeclared | Warning | Rows arrived with no stages: line, so the bands were named "Stage 1", "Stage 2" and so on, ending in "Done" |
| Row short | Warning | A row with fewer counts than stages. The missing counts are padded with zero and drawn as measurements |
| Directive ignored | Warning | A stages:, commit or wip-limit line that was recognised but not used, such as a second stages: line |
| Chart truncated | Gap | Stages, rows or counts past the limits were not read |
Templates: Software Delivery Team, Support Ticket Queue, Hiring Requisition Pipeline, Manufacturing Cell WIP, Video Content Pipeline, Hospital Bed Flow, Mortgage Application Flow, ML Experiment Queue, Newsroom Editorial Pipeline, Incident Backlog Burn-down, Council Planning Applications, Clinical Trial Site Activation and Vulnerability Remediation Queue.
Queueing network
An open queueing network that is solved, not merely drawn.
title "Emergency department — Monday evening"
target 85%
arrivals Triage 12/h
station Triage { servers: 2; service: 8m }
station Assessment { servers: 4; service: 15m }
station Imaging { servers: 3; service: 30m; capacity: 8 }
station Discharge { servers: 3; service: 10m; cv: 1.4 }
route Triage -> Assessment 1.0
route Assessment -> Imaging 0.35
route Assessment -> Discharge 0.65
route Imaging -> Discharge 1.0
route Discharge -> exit 1.0
This network solves as M/M/2, M/M/4, M/M/3/8 and G/G/3, and the figure's verdict reads "Bottleneck: Triage at ρ = 80% on 2 servers — already inside the 85% target; the network is balanced." The network line reads "Offered 12/h · throughput 11.9/h · blocked 0.11/h (0.9%) · L 14.96 in system · W 75.5m end to end · 4 stations", because Imaging's eight places turn a few arrivals away. Change Assessment to servers: 3 and the verdict becomes "Unstable — Assessment is offered 3 erlangs across 3 servers (ρ = 100%), so its queue grows without bound. 4 servers (1 more) would hold ρ at or under 85%."
Statements
| Statement | Also accepted | What it does |
|---|---|---|
station NAME { … } | node, queue, server, resource, desk, stage, centre, center (and their plurals), or a bare NAME { … }. Braces are optional: station Triage servers: 2 service: 8m | A service centre. The block may span several lines |
arrivals [station] RATE | arrival, external, external arrivals, demand, offered; to, at, into, for or of before the name are optional | An outside Poisson stream. With no station named it enters the first station. Several lines add up |
route A -> B 0.35 | The keyword is optional, and flow, link or path also work; arrows ->, -->, =>, →, ➔, ⟶ | A routing probability. A chain such as A -> B -> C becomes two routes. A line that starts with an arrow (continuing the line above) is reported as not read |
target 85% | target utilisation, target rho, target load; 85%, 0.85 or 85 | The utilisation the verdict sizes servers against. Default 85% |
rate unit /h | rate units, rates; per hour also works | Display unit for rates: per second, minute, hour, day, week or shift. Otherwise taken from the first arrival stream |
title "…" | Title. Read only before the first station |
Station keys
| Key | Aliases | Meaning |
|---|---|---|
servers | server, c, agents, channels, lines, bays, desks, staff, operators, seats, workers, executors, pumps, tills, number of servers | Parallel servers, at least 1 and at most 512 |
service | service time, mean service, st, ts, s, duration, handle, handling, aht | Mean service time |
service rate | mu, μ | Service rate instead of time, for example 7.5/h |
capacity | queue capacity, k, buffer, room, limit, spaces, slots | Total allowed in the station, in service plus waiting (at most 512). Makes it a finite-capacity station that turns arrivals away |
cv | service cv, cs, cvs | Coefficient of variation of service time. Default 1 (exponential) |
cva | arrival cv, ca | Coefficient of variation of arrivals. Default 1 (Poisson) |
Some keys are refused on purpose, kept as a label under the station, and reported as a coerced value so you know the number was not used:
| Refused key | Why |
|---|---|
scv, scvs, cs2, scva, ca2 | A squared coefficient of variation. Write cv or cva with the unsquared value; confusing the two is a classic source of wrong answers |
lambda, arrival rate | An outside arrival rate belongs on its own line: arrivals NAME 12/h |
rho, utilisation, utilization | Utilisation is computed from the servers, the service time and the traffic equations, so it cannot be stated |
Any other key, such as owner: or note:, is kept and shown under the station (up to six per station).
Rates are written 12/h, 0.2/s, 450/day, 42/min, 18/shift (an 8-hour shift) or 12 per hour. A bare number is per hour. Route probabilities are 0.35, 35%, p: 0.35 or @ 0.35, and default to 1. A trailing whole number other than 0 or 1 is read as part of the station name, so -> Bay 3 is a station called "Bay 3"; quote a name such as "Line 1" to keep its digit. exit, exits, out, output, sink, end, done, depart, departure, leave, leaves, external, world and none all mean "leaves the network" unless a station has that name. Any probability a station does not route away leaves the network, so -> exit lines are documentation. A station named only in a route or an arrivals line is created with one server and no service time, so a half-typed network still draws. A route or arrivals line may shorten a station's name to its start (-> Assess finds "Assessment") as long as only one station begins that way; a station declaration never matches by prefix.
Which model is used
| You declare | Model shown | Method |
|---|---|---|
Servers and service only (no cv or cva, or both equal to 1), one server | M/M/1 | Exact |
| The same, several servers | M/M/c, shown with the count (for example M/M/3) | Erlang C |
A capacity | M/M/c/K (for example M/M/2/6) | Exact birth–death chain, with blocking. Any cv or cva is ignored and reported |
One server, a cv other than 1 and no cva other than 1 | M/G/1 | Pollaczek–Khinchine (exact) |
Any other combination: several servers with a cv other than 1, or any cva other than 1 | G/G/c (for example G/G/3, or G/G/1) | Allen–Cunneen approximation |
The engine first solves the traffic equations for every station's arrival rate, feedback loops included, then solves each station, then the whole network. For finite-capacity stations, blocking and throughput are solved together until they agree.
What it shows
- Each station is drawn as a waiting-line comb feeding its server circles, laid out left to right in routing order. Outside arrivals enter from the left and exits leave to the right; forward skips arc over the row and feedback loops arc under it, every arrow carrying its probability. Circles are green under 70% utilisation, amber from 70% and red from 85%. The bottleneck carries a bottleneck badge, or saturated if it is unstable. Under each station: λ and ρ; Wq and Lq; W and L; the model (for example M/M/2) with either P(wait), the blocked share for a finite station, or "queue grows without bound"; and any extra keys you wrote.
- The results table lists, per station: Station, Model, c, K (when any station is finite), 1/μ, λ, λ eff (when any station is finite), a (offered load in erlangs), ρ, P(wait), P(block) (when any station is finite), Lq, Wq, L and W.
- The network line reads, for example, "Offered 12/h · throughput 12/h · L 4.31 in system · W 21.6m end to end · 4 stations", adding "blocked …" when a finite buffer turns arrivals away.
- The stability line under it reads "Stable — every station holds ρ below 1…", or explains why waiting times are left blank.
- The verdict is one sentence, coloured green, amber or red.
| Verdict | Meaning |
|---|---|
| "Bottleneck: Triage at ρ = 80% on 2 servers — already inside the 85% target; the network is balanced." (green) | Every station is under target |
| "Bottleneck: Assessment at ρ = 91.7% on 3 servers — 4 servers (1 more) would bring it under the 85% target." (amber, or red from 95%) | The busiest station needs more servers to meet target |
| "Unstable — Imaging is offered 1.2 erlangs across 1 server (ρ = 120%), so its queue grows without bound. 2 servers (1 more) would hold ρ at or under 85%." | A station is at or above 100% utilisation. Its queue results are shown as "—", not infinity |
| "Unsolvable — the traffic equations are singular: a routing cycle sends every job back into the network with no exit. Give one station an exit route." | A loop with no way out |
| "No bottleneck is named and no stability verdict is given — part of this network was not read…" | A size limit was reached |
With no station at all, the figure shows the syntax hint "Describe the network — arrivals 12/h" instead of a verdict. With stations but no arrivals line, every utilisation is 0 and the verdict still names the first station as the bottleneck at "ρ = 0%"; read the No arrivals warning rather than the green sentence.
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Empty network | Error | Nothing was recognised as a station, so nothing was solved |
| Singular routing | Error | A routing loop with no exit; no arrival rate exists |
| Unstable station | Error | A station without a capacity at or above 100% utilisation. Its queue grows without bound, so its Lq, Wq, L and W are shown as "—" |
| Over target | Warning | A station needs more servers to hold the target |
| Station restated | Warning | A station declared twice. The last declaration wins |
| Service unstated | Warning | A declared station with no usable service time, solved as if it took no time |
| Station unreached | Warning | A declared station no traffic reaches |
| Implicit station | Warning | A station named only by a route or arrivals line, given one server and no service time |
| No arrivals | Warning | No outside stream, so every utilisation is 0 |
| Ambiguous name | Warning | A shortened name that matches two stations. The engine refuses to choose and treats it as a station of its own; write the name in full |
| Routing rescaled | Warning | Probabilities leaving one station summed past 1 and were scaled down |
| cv ignored | Warning | cv on a finite-capacity station, which is solved exactly as M/M/c/K and assumes exponential service |
| Line not read | Gap | A line matched no statement, or an arrivals line stated no readable rate |
| Size limit reached | Gap | Part of the network was not read. No bottleneck is named |
| Value coerced | Gap | A value was clamped, rounded or refused, for example servers: 9999 (read as 512), target 150%, a station name over 44 characters, or a refused key |
| Unitless value | Gap | A duration or rate was written with no unit and read as seconds or per hour |
| Assumed target | Gap | No target line, so "inside the target" means the default 85% |
| Downstream of unstable | Gap | A station fed by a saturated one; its figures assume a flow that cannot happen |
| Fixed point unconverged | Gap | With finite buffers in a feedback loop, blocking and throughput did not settle, so the numbers are not a solution |
| Arrivals blocked | Info | A finite buffer is turning arrivals away. Stated because a finite buffer always reads as stable |
Templates: Mass Vaccination Centre, Container Terminal Night Shift, Fleet Telemetry Ingest, Emergency Department, Contact Centre, Airport Security, High-Street Coffee Shop, Warehouse Picking, Checkout API Call Chain, Bank Branch Counter, Car Service Centre, Passport Office Counter and CI Build Farm.
Spaghetti diagram
A lean motion study in which the walking is measured.
title "Nurse motion study — ward B, night shift"
scale 1m = 20px
room "Ward B" 24m x 14m
zone "Clean store" at 1,1 size 4x3
station Desk at 12,7
station Bed1 at 3,6
station Bed2 at 5,11
station "Meds room" at 20,3
path "Nurse A" : Desk -> Bed1 -> "Meds room" -> Bed1 -> Desk
path "Nurse B" colour: amber : Desk -> Bed2 -> "Meds room" -> Desk
scenario "After relayout"
station "Meds room" at 11,4
Statements
| Statement | Also accepted | What it does |
|---|---|---|
room "Name" 24 x 14 | floor, plan, site; room "X" at 2,2 size 20x10 moves its corner | The floor rectangle in real units, origin top-left. Without it, the floor is derived from the stations and zones |
station NAME at X,Y | point, node, location, loc, stop, machine, marker; at is optional and the coordinates may be separated by a comma or a space (station Sink 0 4); a bare Pass at 3,6 works | A place people walk to. Restating a station moves it |
zone "Name" at X,Y size WxH | area, region | A shaded box for context. Never counted in travel |
path "Actor" : A -> B -> C | route, actor, trip, walk, operator, person; arrows ->, →, => or commas; a bare Desk -> Bed1 -> Desk is an unnamed path | One person's round. A leg may end at a literal point written (12,4) |
colour: blue before the final colon | color:, or a hex value such as #2563eb | Pins the actor's colour |
scenario "After relayout" | state, layout, case | Starts the second scenario |
scale 1m = 20px | scale 20px per m, scale 20 | Drawing scale and unit name. Affects only the drawing |
unit ft | units ft | Sets the unit name alone (letters only, up to six). Default m |
title "…" | title: … | Title. The first one wins |
Named colours are blue, red, green, amber, orange, yellow, purple, violet, indigo, teal, cyan, pink, magenta, lime, brown, grey, gray, slate and black. Otherwise colours are assigned in declaration order.
A scenario line written before anything else simply names the first layout (for example scenario "Current layout"); otherwise it is called "Before", and an unnamed second scenario is called "After". The second scenario inherits the first scenario's stations, zones and, if it declares none of its own, its paths, so you restate only what moved. A third scenario line does not get a panel of its own: its content joins the second, and the figure says so. The renderer shrinks the scale to fit, so a 200-metre warehouse and a 6-metre kitchen both come out legible.
What it computes
| Metric | Meaning |
|---|---|
| Travel per actor and in total | Sum of straight-line leg lengths, in your units |
| Legs | Traversals. A retraced leg counts twice |
| Longest leg | The single longest walk between two points |
| Most-travelled leg | The station pair with the most traversals: the link a relayout should shorten first |
| Visits per station | Arrivals and departures. Each station marker carries its count |
| Crossings | Pairs of legs that properly cross. Legs that meet at a shared station, or retrace each other, do not count. Each crossing is ringed |
| Saving | With a second scenario: distance and crossings saved, absolute and as a percentage of the first |
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Station invented | Error | A path names a station no station line placed. It is drawn on a ring inside the floor with a dashed outline, and its distances are not measurements |
| Station name looks like a keyword | Error | For example statoin Meds at 20,3, which creates a station called "statoin Meds" |
| Saving from invented position | Error | A before-and-after saving computed with an invented station on either side |
| Line not read | Error | A line matched no statement |
| No path | Warning | Stations but nobody walks between them |
| Plan truncated | Gap | A size limit was reached |
| Study result | Info | Crossings, the busiest station and the saving, stated as results |
Templates: Nurse Motion Study (Acute Ward), Warehouse Pick Round, Restaurant Kitchen Line, Machine Shop Cell Rebuild, Supermarket Shopper Trip, Office Coffee and Print Runs, Aircraft Turnaround (Stand 14), Hotel Housekeeping Round, Pathology Sample Handling and Construction Site Logistics.
Swimlane process
A cross-functional process diagram with one lane per role or team.
title "Bug triage"
lane "Customer"
lane "Support"
lane "Engineering"
node A "Open ticket" in Customer as stadium
node B "Triage" in Support as diamond
node C "Fix" in Engineering
node D "Verify" in Support
node E "Confirm" in Customer as stadium
A -> B
B -> C : "bug"
B -> A : "need info"
C -> D
D -> E
| Statement | What it does |
|---|---|
title … | Title. If written twice, the last one is drawn |
lane "Name" | Declares a lane. Lanes are drawn top to bottom in the order declared. With no lane line at all, lanes are taken from the steps in the order they first appear, and every step is reported as being in an undeclared lane |
node ID "Label" in LANE | A step. The id is one word; the label is one word or quoted |
… as rect, as stadium, as diamond, as circle | The step's shape. Default rect |
A -> B or A --> B | A flow between two steps |
A -> B : "label" | A labelled flow, such as a decision branch |
Columns are assigned automatically by longest path, so each handoff moves visibly to the right. Rework loops (an arrow back to an earlier step) are recognised first and drawn as loop-backs, so they never reverse the layout. Two steps in the same lane at the same stage are stacked in one cell. A step placed in a lane that was never declared gets a lane of its own rather than being merged into the first.
Step boxes and lane headings are measured and wrapped to fit. Up to three error and warning findings are printed on the figure (then "…and N more"), with notes for anything the renderer could not draw: labels shortened with an ellipsis (named by id), steps in undeclared lanes ("drawn in a lane of their own, not merged into the first"), and arrows that name an undeclared step ("not drawn"). A shortened label is also listed as an Info finding with its full wording; every check uses the full text. A line longer than 2,000 characters is not read. With nothing to draw, the figure shows "Add a lane and some nodes — lane "Customer", node A "Open" in Customer".
| Finding | Level | Meaning |
|---|---|---|
| Decision with one way out | Error | A diamond with fewer than two outgoing flows |
| Arrow names an undeclared step | Warning | The arrow cannot be drawn |
| Lane undeclared | Warning | A step names a lane with no lane line |
| Node redeclared | Warning | The first declaration is drawn; the second is ignored |
| Decision unlabelled | Warning | A diamond with an unlabelled branch |
| Decision duplicate label | Warning | Two branches with the same label |
| No exit | Warning | No step without an outgoing flow, so the process never finishes |
| Unreachable step | Warning | A step, other than the first one declared, that nothing leads to |
| Lane empty | Warning | A declared lane with nothing in it |
| Line not read | Gap | A line matched no statement. The finding explains the expected form |
| Empty process | Gap | No step declared |
Templates (26) include Bug triage, Procurement, Hiring loop, Content publishing, Loan approval, Incident response, Employee onboarding, Refund request, Supplier onboarding, Enterprise sales cycle, Sepsis Six Pathway, Goods Receipt Price Dispute, Planning Objection Handling, Pharmacy Dispensing Standard Work and Emergency change (ECAB approval and back-out). For a process to the BPMN 2.0 standard with linting and token simulation, use the BPMN studio.
Kanban board
A board of columns and cards with WIP limits.
title "Sprint 47"
column "To do"
card "Design login screen" assignee "Eva" priority high
card "Wire up SSO" assignee "Marco" priority medium tags "auth,sso"
column "In progress" wip 2
card "Build API" assignee "Sam" priority urgent
column "Done"
card "Spec & RFC" assignee "Eva"
| Statement | What it does |
|---|---|
title "…" | Title. If written twice, the last is drawn and the earlier one is reported |
column "Name" | Opens a column. Quote the name when it contains a space |
column "Name" wip 3 | A column with a WIP limit. The limit is a whole number |
card "Title" | A card in the column above it |
… assignee "Eva" | Shown as a round chip with the first two letters of the name ("EV"), followed by the name. Quote names with spaces |
… priority low, medium, high or urgent | A coloured edge stripe: green, blue, amber or red. Any other word is no priority |
… tags "a,b" | Comma-separated tags. Quote the list |
Each column header shows its card count, and its WIP limit when one is declared; the badge turns to the alarm colour when the count exceeds the limit. A card with no priority gets a neutral assignee chip, distinct from priority medium.
Column headers and card titles are measured and wrapped, and every declared tag is drawn as a chip. Lines the engine cannot read are listed in a notice band under the board ("N things in this source are not on the board above:"), up to six at a time, with the form it expected. This matters most for a mistyped column line: the cards under it are drawn in the column above, and the notice says so ("The 2 cards written after it are drawn in "To do", the column declared above it."). A card written before any column line is not on the board, and the notice says that too. With no column at all, the board shows "Add a column — column "To do" / card "Task"".
| Finding | Level | Meaning |
|---|---|---|
| WIP exceeded | Error | A column holds more cards than its wip limit |
| Card outside a column | Error | A card line before any column line; it is not on the board |
| Card title empty | Warning | A card with no title text |
| Title redeclared | Warning | Two title lines; the last is drawn |
| Line not read | Gap | A line the engine could not read. For a column line, the cards under it are drawn in the column above |
| Board empty | Gap | No column or card was read |
Templates (21) include Sprint board, Support queue, Hiring pipeline, Editorial calendar, Product launch, Bug board, DevOps board, Classroom projects, Research lab, Personal weekly board, Hospital Estates Maintenance, Investigations Desk, Clinical Trial Site Start-Up and Planned Substation Outage Board. To measure flow across a board over time, use Flow metrics (CFD).
Service Blueprint
A Lynn-Shostack service blueprint with five lanes and the three standard dividers.
title: Restaurant Order
subtitle: Sit-down dining experience
evidence: Signage | Menu card | Plated food | Bill | Receipt
customer: Arrives → Reads menu → Orders → Waits → Eats → Pays → Leaves
frontstage: Greet & seat | Present menu | Take order | Serve food | Bill | Farewell
backstage: Reserve table | Check stock | Cook order | Plate up | Settle till
support: POS | Inventory DB | Kitchen workflow | Accounting
| Key | Lane or role |
|---|---|
title: and subtitle: | Heading |
note: | A note. Repeatable |
evidence: | Physical evidence: what the customer touches or sees |
customer: | The customer journey. The line of interaction follows it |
frontstage: | What employees do in view. The line of visibility follows it |
backstage: | What employees do out of sight. The line of internal interaction follows it |
support: | Systems and partners behind the lanes above |
Every line is key: value, with the colon required (so title: Restaurant Order, not title "…"), and keys are case-insensitive. Steps within a lane are separated by |, → or ->. The lanes are labelled Physical evidence, Customer journey, Frontstage actions, Backstage actions and Support processes. They are always drawn in that order, whatever order you write them in, and a lane you leave out draws as a thin empty track so the column grid stays aligned. When a lane has many steps the figure grows wider rather than squeezing the boxes. Only a # at the start of a line is a comment in this engine.
| Finding | Level | Meaning |
|---|---|---|
| Line not read | Error | A line that is not key: value, dropped whole |
| Unknown key | Error | A key that is not one of the eight above, such as a mistyped fronstage:. The lane it was meant to open draws empty |
| Lane repeated | Error | The same lane written twice; the later line replaces the earlier |
| Lane empty | Warning | A lane key with no steps after it |
| Step clipped | Warning | Step text too long to fit its box |
| Journey missing | Warning | No customer: lane, so the dividing lines separate nothing |
| Lane absent, ragged columns, figure widened | Info | A lane left out (drawn as an empty track); lanes with different step counts (steps line up by position in their lane, not by meaning); or a figure drawn wider than requested so every step box stays readable |
Templates: Restaurant order, E-commerce checkout, Telehealth visit, Bank account opening, SaaS trial to paid, Customer support ticket, Hotel check-in, Hospital discharge, Airline booking and Developer onboarding.
Quality and improvement
SIPOC
The Six Sigma define-phase scoping diagram, which also checks itself.
title "New patient registration"
scope "Referral received" -> "Confirmation sent to patient"
owner "Access services team"
metric "Referral-to-appointment days" target: 14 actual: 19 unit: days
metric "First-pass referral acceptance" target: 95% actual: 88% better: higher
suppliers: Referring GP practice, Insurer, Patient
inputs:
- Referral letter
- Insurance eligibility response
- Patient demographics
process: Receive referral -> Verify eligibility -> Create record -> Book appointment -> Send confirmation
outputs: Booked appointment, Confirmation letter, Updated record
customers: Patient, Outpatient clinic, Billing office
requirement input "Referral letter": "Complete, legible, dated within 30 days" (CTQ)
ctq output "Booked appointment": "Within 14 days of referral receipt"
Statements
| Statement | Also accepted | What it does |
|---|---|---|
suppliers: | s:, supplier:, source:, sources:, vendor:, vendors: | Opens the Suppliers column |
inputs: | i:, input: | Opens the Inputs column |
process: | p:, processes:, process step:, process steps:, step:, steps: | The process steps |
outputs: | o:, output: | Opens the Outputs column |
customers: | c:, customer:, client:, clients: | Opens the Customers column |
title "…" | title: … | The title. The first one wins |
scope "A" -> "B" | → or => for the arrow; a prose sentence such as scope "From referral received to first appointment booked" (to, through, until or thru) | The process boundaries. Any other text is shown as written, with no boundary check. The first one wins |
owner "…" | process owner | The process owner, shown as a tile. The first one wins |
metric "Name" target: … actual: … | metrics; goal: or spec: for target; current:, baseline: or today: for actual; unit: or units:; better: or direction: with lower or higher (also less/more, min/max); the phrases higher is better and lower is better; a bare value after the name is the target | A header metric tile with its variance. Up to five metrics |
requirement input "Item": "text" | req, require; columns input, output, supplier, customer | A requirement chip under an item |
ctq output "Item": "text" | A trailing (CTQ) in the text | A requirement flagged critical to quality |
Items on a column line are comma-separated; quote an item to keep a comma inside it. A - bulleted line beneath a column adds exactly one item, verbatim. A column opened twice accumulates. Process steps split on ->, →, | or ; when any is present, and on commas otherwise; leading numbering such as 1. or 2) is stripped because the engine numbers the steps itself. Requirements may be written before the column they refer to, and items are matched loosely (case, plurals and partial phrases). better: defaults to lower, because define-phase metrics are mostly times, backlogs and defect counts; write better: higher for yields and acceptance rates.
What it computes
The notes strip reports item counts per column and the number of steps; requirement gaps (each input and output with no stated requirement, named); requirement coverage; the scope check (whether the declared start matches step 1 and the declared end the last step, matched loosely so "Receive referral" and "Referral received" agree); and each metric's variance against target in the declared direction. The figure shows a header strip (title, scope, owner and metric tiles), five aligned columns, the process as a numbered chevron spine (wrapping at five steps a row) and requirement chips under their items.
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Column misfiled | Error | A word: line under an open column whose word names no column, so the whole line became items |
| Line dropped | Error | A line before any column opened |
| Orphan requirement | Error | A requirement whose item was not found |
| Metric unparsed | Error | A metric line that could not be read |
| Requirement unparsed | Error | A requirement or ctq line that could not be read |
| Metric valueless | Warning | A metric with neither target nor actual |
| Empty column | Warning | A column with no items |
| Truncation | Gap | A size limit was reached |
| Counts, input and output requirement gaps, scope declared, scope start and end, metric variance | Info | The SIPOC's own results. A requirement gap or a scope mismatch is stated, not scored against the figure |
Templates: Blood Bank Unit Issue, Narrowbody Aircraft Turnaround, Clinical Coding to Invoice, Inpatient Discharge, Injection Moulding Cell, Sev-1 Incident Response, Accounts Payable Invoice to Pay, Cold Chain Vaccine Despatch, Undergraduate Enrolment, Offshore Turbine Service, Householder Planning Permission, Omnichannel Apparel Returns and Clinical Trial Site Activation.
Control chart (SPC)
Statistical process control charts whose centre line and limits are computed from your data, never typed in.
title "Fill volume — line 3"
chart xbar-r
unit ml
spec lsl: 495 usl: 505 target: 500
labels: 06:00, 07:00, 08:00
rules: all
subgroup 500.1 499.8 500.4 500.0
subgroup 500.9 501.2 500.7 500.5
subgroup 499.6 500.1 499.9 500.2
Three subgroups are enough to draw, but only just: this example reads "Out of control — 1 of 3 points flagged by rule 1." and carries a rule-window gap, because six of the eight rules need longer runs. A real study wants twenty or more subgroups.
Attribute charts take counts:
chart u
unit "infections per 1,000 catheter-days"
sample n: 1.18 defects: 3
sample n: 1.24 defects: 1
sample n: 0.97 defects: 4
Statements
| Statement | Also accepted | What it does |
|---|---|---|
chart TYPE | type; see the chart table below | The chart type. Optional: inferred from the data when absent |
subgroup 1 2 3 | subgroups, group, groups, sg, sub, batch; numbers separated by spaces, commas or semicolons | One subgroup of measurements |
value 12.1 | values, point, points, x, obs, observation, observations | Individual readings, one point each |
| A bare line of numbers | Data, so pasted columns work | |
sample n: 1180 defects: 62 | d:, count:, c:, np:, x:, nonconforming: or events: for the count; size:, units: or area: for n; two bare numbers (n, then count); a bare n: 200 d: 7 line | Attribute data. n may be fractional: for a u chart it is an area of opportunity |
spec lsl: … usl: … target: … | specs, specification; lower or min, upper or max, nominal; keys in any order; positional numbers (spec 495 505 500); separate lsl: 495, usl: 505 or target: 500 lines | Specification limits. Turns on capability |
labels: a, b, c | label:; commas or semicolons | Tick labels for the x axis (shortened past 14 characters) |
rules: all | rule; on, yes, a list such as 1,2,5, or off (none, no) | Which Nelson rules to run. Default all eight |
unit ml | units | The unit, up to 40 characters |
title "…" | Title. Read only before the first data line |
| Chart | You can write | Data | Limits |
|---|---|---|---|
| I-MR | i-mr, imr, xmr, i, individual, individuals, mr | Individual readings | Sigma from the mean moving range ÷ d2 |
| X̄-R | xbar-r, xbarr, xr, meanrange | Subgroups of 2 to 25 | X̿ ± A2·R̄; range limits D3·R̄ to D4·R̄ |
| X̄-S | xbar-s, xbars, xs, meansigma | Subgroups of 2 to 25 | X̿ ± A3·s̄; sigma limits B3·s̄ to B4·s̄ |
| p | p, pchart, proportion, fraction | Defectives out of n | p̄ ± 3√(p̄(1−p̄)/nᵢ), stepped per point |
| np | np, npchart, count | Defectives out of n | nᵢp̄ ± 3√(nᵢp̄(1−p̄)) |
| c | c, cchart, defects | Defect counts | c̄ ± 3√c̄ |
| u | u, uchart, rate | Defects over an area of opportunity | ū ± 3√(ū/nᵢ), stepped per point |
The chart word is read with case, spaces and punctuation ignored, so xbar-r, XbarR and xbar r are the same; xbarrange and xbarsigma are also accepted. An unrecognised chart word is ignored and the type is inferred. With no chart line, counts give a p chart (or c when no n is given), subgroups of one give I-MR, subgroups of nine or more give X̄-S and anything else gives X̄-R. A mismatched pairing corrects itself: chart i-mr with wide subgroups flattens them into individuals rather than refusing to draw. When subgroup sizes vary, the limits step per point. On the attribute charts (p, np, c and u) a lower limit never goes below zero. Variables charts use the published constants table for subgroups of 2 to 25.
What it computes
- Nelson rules. Each violation is marked on the point that completes the pattern and listed as, for example, "Rule 2 · X̄ at point 14 = 501.20 — 9 points in a row on one side of the centre line". Up to six are listed. Only rule 1 is applied to the range or sigma panel.
- Verdict. "In control — 24 points, no Nelson-rule violations." or "Out of control — 5 of 24 points flagged by rules 1, 2."
- Capability. With specification limits: Cp and Cpk from within-subgroup sigma, Pp and Ppk from overall sigma, and expected parts per million out of specification. Capability quoted for an out-of-control process adds "Quoted from an unstable process, so treat it as provisional."
| Rule | Pattern |
|---|---|
| 1 | 1 point beyond a 3σ limit |
| 2 | 9 points in a row on one side of the centre line |
| 3 | 6 points in a row steadily increasing or decreasing |
| 4 | 14 points in a row alternating up and down |
| 5 | 2 of 3 points beyond 2σ on the same side |
| 6 | 4 of 5 points beyond 1σ on the same side |
| 7 | 15 points in a row within 1σ of the centre line |
| 8 | 8 points in a row beyond 1σ, either side |
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Reading not read | Error | A non-number among the readings, so the chart has one point fewer than you typed |
| Directive misread | Warning | A line whose first word is one letter from a keyword (for example spek lsl: 5) was charted as data |
| Rules disabled or narrowed | Gap | rules: off, or a subset, so some patterns were not looked for |
| Rule window unreachable | Gap | Too few points for a rule's pattern to be possible. Rule 7 needs 15 points and rule 4 needs 14, so any chart shorter than 15 points carries this gap with all eight rules on; write rules: 1,5 (or whichever rules the run is long enough for) to say so deliberately |
| Limits not estimable | Gap | Not enough data to estimate limits |
| Run truncated | Gap | More than 400 points. "In control" is never claimed ("Not assessed — part of this run was not read…"), an out-of-control count is shown with "≥", and capability reads "Cp and Cpk are not stated — part of this run was not read…" |
The chart needs at least two subgroups before limits can be estimated. Templates: I-MR (Tablet Press Weight, Stroke Door-to-Needle Time, API p95 Latency, Reactor Peak Exotherm), X̄-R (Bottle Fill Volume, API Assay Concentration, Paint Film Thickness), X̄-S (Moulded Boss Diameter), p (Call Abandon Rate), np (Invoice Error Count), c (Reflow Solder Defects, Body-in-White Weld Defects) and u (Central-Line Infections).
Pareto chart
The 80/20 chart with its headline sentence derived from the data.
title "Customer complaints — H1 2027 vs H2 2026"
unit complaints
period "H1 2027"
compare "H2 2026"
threshold 80%
other-below 2%
max-bars 12
note "Excludes wholesale accounts"
"Late delivery" 412 351
"Damaged packaging" 227 254
"Wrong item shipped" 141 132
"Billing error" 96 88
Unhelpful agent 64 71
| Directive | Also accepted | What it does |
|---|---|---|
title, note | Free text, quoted or bare, up to 140 characters. The first title wins; a later note replaces an earlier one | |
unit | units | What one count is, such as "complaints", "minutes" or "GBP thousands" |
period | series, current | Name of the charted series |
compare | vs, versus, prior, baseline | Name of the comparison series |
threshold 80% | cut, vital few, vital-few, vital | The vital-few cut. Default 80%, clamped to 1–100 |
other-below 2% | fold-below, tail-below, other, fold | Fold categories under this share of the total into Other. Clamped to 0–50% |
max-bars 12 | max-categories, top, bars | Fold everything past this many bars into Other. Default 15, from 2 to 30 |
A data line is a label followed by one or two numbers: the charted period, then optionally the comparison period. A line that opens with a quoted label is always data, so quote a label when it would collide with a directive ("Note failures", "Top cover cracked") or ends in digits. Separators are flexible: Late delivery: 412, Late delivery = 412, Late delivery | 412 351 and Late delivery, 412, 351 all work, and a leading - or * bullet is stripped. Repeated labels are added together, so a tally typed off a check sheet works. Numbers accept 1,234 and 1_234; write the two periods separated by a space so 412 210 is never read as 412,210. A trailing % on a value is ignored. Zero, negative and unreadable values are dropped and reported. A line longer than 2,000 characters is not read, and the tally is then treated as incomplete.
What it computes: each category's share; the running cumulative percentage; the vital few (the leading categories up to and including the one whose bar crosses the threshold); the share they carry; and the Pareto ratio sentence, for example "3 of 11 categories (27%) account for 81.2% of 1,040 complaints". With a comparison period it draws ghost bars and a dashed curve accumulated in the current period's order, and lists the categories that entered or left the vital few. Other is always drawn last and never counted among the vital few. A single category is never folded on its own. The count axis is scaled to the tallest bar so every bar stays readable, while the cumulative curve keeps its own 0–100% axis.
What it checks: a row that could not be read, a value that is not a count, a comparison column that cannot be used (all Error); a zero value and rows discarded past a limit (Gap); labels merged because they repeat, and a directive misread as a data row (Warning). If a size limit is reached, no ratio sentence is written.
Templates: Rail Delay Minutes by Cause, Heat Pump Warranty Claims, Drug Round Interruptions, 30-Day Hospital Readmissions, Injection Moulding Defects, Mobile Crash Signatures, Card Chargeback Reasons, Parcel Network Late Deliveries, First-Year Student Withdrawals, Wind Farm Unplanned Downtime, Council Service Complaints, Retail Stock Loss, Clinical Trial Data Queries and Customer Revenue Concentration.
Fishbone (Ishikawa)
Root-cause diagrams with the problem at the head and categories alternating above and below the backbone.
title "OTIF review"
problem "Late delivery"
category "People"
cause "Untrained staff"
cause "Sick days"
category "Process"
- Manual handoffs
- No SLAs
category "Equipment"
Forklift downtime
| Statement | What it does |
|---|---|
title "…" | Title |
problem "…" | The effect, in the head box. Wrapped to up to four lines |
category "…" | Opens a rib |
cause "…", - … or • … | A cause on the current rib |
| Any other line under a rib | Taken as a cause, verbatim |
If no category line is written, four ribs are supplied: People, Process, Equipment and Materials. If no problem line is written, the head reads "Problem". Any other line written before the first category is not on the figure and is reported. The title and problem lines may come anywhere; if either is written twice, the last one is drawn. The canvas widens (by up to 800 px) to hold long causes; a cause or problem too long even for that is shortened with an ellipsis and written out in full in the notice band under the figure, which lists up to five at a time.
| Finding | Level |
|---|---|
| Categories unstated (the four default ribs were supplied) | Error |
| Problem unstated | Error |
| Cause before any category (not on the figure) | Error |
| Category with no causes; category name repeated; cause repeated in a category; problem or title restated; empty cause, problem or category name | Warning |
| The same cause under two categories | Info |
Templates include 6 Ms late delivery, Production bug, Low signup conversion, Manufacturing defect rate, Customer churn, Site outage, Slow hiring funnel, Pharmaceutical Batch Deviation, On-Time In-Full Miss, Day-of-Surgery Cancellations, Short-Notice Train Cancellations and Fraud Model Precision Drop. A fishbone pairs naturally with a Pareto chart of how often each cause occurs.
Design structure matrix
Dependency matrices with partitioning, for process sequencing, component coupling, team interfaces or design parameters.
title "Vehicle programme dependencies"
mode process
convention ir-fad
elements: Concept, Styling, Packaging, Body, Chassis, Powertrain, Testing
Styling <- Concept
Packaging <- Concept, Styling
Body <- Packaging, Styling(2)
Chassis <- Packaging
Powertrain <- Concept, Packaging
Testing <- Body, Chassis, Powertrain
Styling <- Testing
| Statement | What it does |
|---|---|
A <- B, C | A takes input from B and C. ← and <-- also work. Both sides take a comma list, so A, B <- C works too |
A -> B, C | A feeds B and C. → and --> also work |
A depends on B | The same as A <- B |
Name(2) or Name:2 | Dependency strength from 1 to 9 (default 1). Shades the mark, and is shown as a digit when the cell is big enough |
elements: … | Fixes the as-declared order. Also activities:, components:, teams:, parameters:, tasks:, nodes:. Optional and repeatable |
| A line with no arrow | Declares one element, so a long header can be written one name per line |
mode process | process, component, team or parameter (plurals and shortened forms also work). Default process |
convention ir-fad | Inputs in rows, feedback above the diagonal (the default, and what any other word means), or ic-fbd (also ic, icfbd, fbd, col, cols, column, columns, inputs-in-columns), the transpose. The figure prints which is in force |
legend off | Hides the legend (no, none, false, hide, hidden and 0 also work) |
title "…" | Title. Read only before any other content |
Names are matched without regard to case, so "Body-in-white" and "body-in-white" merge, and the first spelling is the one drawn. A name used in a dependency but never declared is appended in order of first mention. Self-dependencies are dropped. Because any line without an arrow declares an element, a mistyped keyword line such as elemnts: Body, Chassis becomes one element with that whole text as its name; the check below catches it. The engine computes the cycles (groups that depend on each other), a partitioned order that pushes as many dependencies as possible below the diagonal, the iteration blocks that must be worked together, and the count of feedback marks before and after, for example "23 feedback marks reduced to 6 across 2 iteration blocks". The figure shows the declared and partitioned matrices side by side, with iteration blocks boxed and fan-in and fan-out counts on the right. It checks for a line whose first word is one letter away from a declaration keyword, such as elemnts: … or mod process, and so was not read as the declaration you meant (Warning); self-dependencies, which are dropped (Warning); and a size limit reached (Gap), in which case no sequencing verdict is given.
Templates: EV Vehicle Programme, Checkout Service Coupling, Hospital EHR Go-Live, Payments Team Topology, Goods-to-Person Retrofit, MSc Programme Validation, Offshore Wind Farm Delivery, Benefit Claim Service Redesign, Retail Recommender Platform, Pre-Training Parameter Coupling, Aircraft Cabin Retrofit, Payments Monolith Decomposition, Marketing Authorisation Dossier and an application landscape interface matrix.
Risk, safety and reliability
Fault tree (FTA)
Quantitative fault-tree analysis in IEC 61025 notation, computed exactly.
title "Loss of reactor cooling"
mission 8760h
top "Reactor cooling lost" = AND(pump_fail, backup_fail)
gate pump_fail "Main pump train fails" = OR(motor, power, control)
gate backup_fail "Backup train fails" = KOFN(2, dg1, dg2, dg3)
gate control "Control loop fails" = INHIBIT(ctl_fault, high_temp)
event motor "Pump motor failure" p=0.02
event power "Bus power loss" rate=1.2e-6
event ctl_fault "Controller fault" mtbf=45000h
condition high_temp "Coolant above 320 C" p=0.15
undeveloped dg1 "Diesel generator 1" p=0.03
undeveloped dg2 "Diesel generator 2" p=0.03
undeveloped dg3 "Diesel generator 3" p=0.03
house maint "Train A out for maintenance" off
Statements
| Statement | Symbol | What it does |
|---|---|---|
top [id] ["Label"] = EXPR | Rectangle | The root. top event also works, and : may replace =. The id defaults to top. top = pump_fail makes an existing gate or event the root. With no top line, the gate nothing else references becomes the root |
gate id ["Label"] = EXPR | Rectangle with its gate symbol | An intermediate event. intermediate and int are aliases, and id = EXPR works without the keyword |
event id ["Label"] attrs | Circle | A basic event. basic and be are aliases |
undeveloped id … | Diamond | An event not developed further. undev is an alias |
house id … on or off | House | A boundary condition, probability 1 or 0. true/false, yes/no and enabled/disabled also work |
condition id … | Oval | A conditioning event for INHIBIT. cond is an alias |
mission 8760h | Mission time, used to turn rates into probabilities. mission time, exposure, exposure time, time and t also work, and the line may come anywhere. Default one year (8760 h), shown as "(default)" | |
title "…" | Title. Read only before the first gate or event |
| Gate | Also written | Meaning |
|---|---|---|
AND(a, b) | ALL(…), a & b, a * b, a · b | All inputs must occur |
OR(a, b) | ANY(…), a + b, or a pipe character between the inputs | Any input suffices |
KOFN(2, a, b, c) | VOTE, ATLEAST, MOFN, shorthand 2OF3(a, b, c), 2OO3(…) or 2/3(…) | At least k of n inputs. Drawn as an OR shield labelled k/n. A k above n is cut to n |
INHIBIT(x, cond) | INHIBIT(x, condition: cond) | x occurs while the condition holds. Drawn as a hexagon with the oval beside it |
The keyword form also works without parentheses: OR a, b, c. A gate keeps its first 12 distinct inputs; the rest are counted and reported, and the tree is then treated as truncated. An unknown operator is computed and drawn as OR with a Warning, so the branch keeps drawing. XOR, NOT, NAND and NOR are also computed as OR, and are reported as an Error: they make the tree non-coherent, and the picture would then be defensible while the arithmetic under it describes a different tree.
| Event attribute | Aliases | Converted to a probability by |
|---|---|---|
p | prob, probability, q, unavailability, or a bare number; pct or percent for a percentage | Used as written. A value outside 0 to 1 is clamped and reported |
rate | lambda, λ, freq, frequency | 1 − e^(−λt) over the mission time, λ per hour. A unit after the number converts it, so rate=1.2e-6 /y is per year |
mtbf | mttf | λ = 1 ÷ MTBF. A bare MTBF is in hours; 45000h, 5 y and similar also work |
fit | λ = FIT × 10⁻⁹ per hour |
Attributes may be written key=value or key: value, in any order.
What it computes
| Tile or panel | Meaning |
|---|---|
| Top event probability (exact) | Computed exactly with a binary decision diagram, which stays correct when one basic event feeds several branches. The rare-event approximation is printed beside it so you can see how far that shortcut is off |
| Top event probability (bound) | Shown instead when the tree is too large for the exact method: a minimal-cut-set upper bound, labelled as such |
| Minimal cut sets | The count, with "+" when enumeration stopped at 2,000. The panel lists them by order (size), then probability, up to ten |
| Smallest cut set order | 1 means a single component can cause the top event |
| Single points of failure | Order-one cut sets, highlighted on the tree. Reads "none" only when there are none |
| Mission time | As declared, or "(default)" |
| Repeated basic events | Events that feed more than one branch, when there are any |
| Importance table | Birnbaum (where design effort pays), Fussell–Vesely (share of current risk through each component) and criticality. Up to eight rows |
Each node's probability is printed beneath it. A gate used in two places is drawn once and referenced elsewhere by a transfer triangle. The panel's first line reads "Exact top-event probability … · rare-event sum ΣP(cut set) …", followed by how far the usual approximation overstates this tree. When a size limit cut part of the tree (including a gate with more than 12 inputs), the panel opens with "This tree was truncated — no top-event probability is stated.", the top tile reads "Top event probability (withheld)" with "—", and the cut-set and single-point tiles show "≥" and "(partial)".
When the tree cannot be analysed. In four cases nothing is computed, and the figure is replaced by an error card with the title, the reason and "Fix the structure and the tree redraws — nothing else was lost."
| Error card | Cause |
|---|---|
| "No top event — write top "Something fails" = AND(a, b)" | The root does not resolve to any gate or event the tree declares |
| "Cyclic gate reference: a then b — a fault tree must be acyclic." | A gate reaches itself through its inputs |
| "70 basic events — exact analysis is capped at 64." | More than 64 distinct basic events are reachable from the top |
| "The tree has no basic events to compute with." | Every branch ends at a gate |
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Cycle, no top event, top unreadable | Error | The tree has no usable shape |
| Gate unreadable | Error | A gate's inputs could not be read, so the gate is dropped. If another gate refers to it, its id is drawn as an undeveloped diamond at p = 0 |
| Non-coherent gate | Error | XOR, NOT, NAND or NOR, computed as OR |
| Unknown operator | Warning | An operator the engine does not know, computed as OR |
| Undeclared event | Warning | A gate names an id nobody declared; it is carried at p = 0 |
| Event with no probability | Warning | A declared event with no p, rate, mtbf or fit; carried at p = 0 |
| Value out of range | Warning | A probability outside 0 to 1, clamped |
| Gate restated | Warning | A gate or event declared twice; the last wins |
| Contested top | Warning | No top line and several unreferenced gates, so the root was picked from among them |
| Assumed top | Info | No top line; the one unreferenced gate became the root |
| Assumed mission | Gap | Rates were converted over the default 8760 h |
| Gate input unread, line not read, size limit reached | Gap | Part of the document never reached the arithmetic |
| Too many basic events, no basic events | Gap | The two error cards above: the tree was not analysed |
| Inexact evaluation | Gap | The exact method ran out of room; the top figure is a labelled upper bound and the importance measures are approximate |
| Cut sets truncated | Gap | Enumeration stopped at 2,000 cut sets |
| Single point of failure | Info | A component that takes the top event on its own. A fact about the system, not a mistake in the document |
Templates: Metro Signalling Loss, Vaccine Cold Chain Excursion, Offshore Turbine Unavailability, Reactor Decay Heat Removal, Triple Hydraulic Loss, Data Centre Power to IT Load, Piped Medical Oxygen, Total Loss of Vehicle Braking, Blowout Preventer on Demand, Wrong-Side Signalling Failure, AV Pedestrian Detection, Regional Cloud API Outage and Batch Reactor Overpressure.
Bowtie risk
Threats on the left, the top event at the knot, consequences on the right, and preventive and recovery barriers on every path, with residual risk computed.
title "Loss of containment — LPG storage"
hazard "LPG stored under pressure"
top "Loss of containment"
unit "/yr"
threat "Corrosion of vessel wall" likelihood: 0.1 {
barrier "Inspection programme" effectiveness: 0.8 type: detection
barrier "Cathodic protection" effectiveness: 0.6
escalation "Inspection deferred for turnaround" {
control "Deferral requires VP sign-off"
}
}
consequence "Vapour cloud explosion" severity: 5 {
barrier "Gas detection + ESD" pfd: 0.15
barrier "Emergency response" 50%
}
Statements
| Statement | Also accepted | Value |
|---|---|---|
title, hazard, top, unit | haz for hazard; top event or event for top; per for unit | The header. Read only before the first threat or consequence, so a threat called "Top-up line rupture" is never mistaken for one |
threat NAME likelihood: 0.1 | cause, source; value keys l, p, prob, probability, freq, frequency, rate | A frequency (events per period), so residual frequencies add at the knot |
consequence NAME severity: 5 | outcome, impact; value keys sev, s, loss, magnitude | Severity on any scale you use; risk carries the same units |
barrier NAME effectiveness: 0.8 | safeguard, defence, defense; value keys eff, e, reliability, rel, works, success; pfd: (also failure, failurerate, fail, pf) is inverted for you, so pfd: 0.1 is the same barrier as effectiveness: 0.9 | Probability the barrier works. type: prevention, detection, control, mitigation or recovery is a caption only |
escalation NAME | escalation factor, ef, degradation | Hangs under the barrier above it: what stops the barrier working |
control NAME | degradation control | A degradation control under the escalation above it. At path level, with no escalation open, it is read as a barrier |
Braces are optional: barrier attaches to the latest threat or consequence, escalation to the latest barrier and control to the latest escalation. ; and new lines both end a statement. A bare trailing number such as barrier "Deluge" 60% is the statement's natural quantity, but only when the line has no key: value pairs. Values accept 0.8, 80% or 80.
What it computes
| Result | How |
|---|---|
| Residual threat frequency | Likelihood × product of (1 − effectiveness) over the threat's barriers |
| Top event | Sum of residual threat frequencies; the tile also shows the inherent frequency |
| Consequence frequency | Top-event frequency through that consequence's recovery barriers |
| Consequence risk | Consequence frequency × severity |
| Residual risk | Sum of consequence risks; the tile also shows the inherent risk with every barrier removed |
| Risk reduction | 1 − residual ÷ inherent; the tile also shows the threat-side effect |
| Barriers | Count, with threats and consequences |
| Dominant threat | The threat carrying the largest share of the top event |
| Barrier criticality | Residual risk recomputed with that one barrier deleted, minus the current residual risk. Up to six are ranked |
Line weight shows each path's share of the risk, and barriers are coloured by effectiveness.
Defaults and caps. A threat with no likelihood is assumed 0.1, a consequence with no severity 3, and a barrier with no effectiveness 0.5. Each assumption is listed. Effectiveness is capped at 0.99, because a barrier that cannot fail does not exist.
| Finding | Level | Meaning |
|---|---|---|
| Single barrier | Warning | A path defended by fewer than two barriers |
| Uncontrolled escalation | Warning | An escalation factor with no degradation control |
| Inert barrier | Warning | Removing the barrier changes the residual risk by exactly nothing: a paper barrier, credited zero effectiveness or sitting on a path that carries no risk |
| Non-conforming value | Warning | A value that could not be used as written: unreadable, below zero, or above the 0.99 effectiveness cap |
| Restated | Warning | Something declared twice, with one of the two discarded |
| Unterminated quote | Warning | A quotation mark that is never closed |
| Assumed independence | Gap | Three or more barriers on a path multiplying out to more than a 100-fold reduction. Common-cause failure is not modelled, so treat that reduction as an upper bound |
| Assumed input | Gap | A likelihood, severity or effectiveness the engine substituted |
| Not read, orphaned statement, size limit reached | Gap | A statement the engine does not know, a statement with nothing to attach to (such as a barrier before any threat), or a part of the document past a limit |
| Concurrent consequences | Info | Several consequences, each credited the full top-event frequency |
When any part of the bowtie was not read (a statement the engine does not know, an orphaned statement, a size limit or an unclosed quotation mark), the Top event, Residual risk and Risk reduction tiles show "—" with "(withheld)", and Barriers is marked "(partial)" with "≥" counts. Otherwise the five tiles are Top event (with the inherent frequency beneath), Residual risk (with the inherent risk), Risk reduction (with the threat-side effect), Barriers (with the threat and consequence counts) and Dominant threat (with its share of the top event). A barrier criticality ranking (up to six) and up to seven findings are printed along the bottom. Templates: LPG Storage Loss of Containment, Wrong-Dose Medication on an Acute Ward, Runway Incursion, Dropped Object from a Drilling Derrick, Ransomware Encryption of Production Systems, Listeria in Chilled Ready Meals, Fall from Height on Steel Erection, Unauthorised Trading, Embankment Dam Overtopping, Customer Data Exfiltration from Cloud Storage, Unsafe LLM Response, Signal Passed at Danger, Ransomware on a Hospital Network and Undeclared Allergen in a Ready Meal.
Reliability block diagram
System reliability, MTTF and availability, computed from series, parallel, k-out-of-n and standby arrangements.
title "Redundant power train"
mission 8760h
block grid "Grid supply" mtbf: 4000h mttr: 6h
block ups1 "UPS A" r: 0.98
block ups2 "UPS B" r: 0.98
block pdu1 "PDU 1" mtbf: 260000h
block pdu2 "PDU 2" mtbf: 260000h
block pdu3 "PDU 3" mtbf: 260000h
block pumpA "Pump A" rate: 2.5e-5 /h
block pumpB "Pump B" rate: 2.5e-5 /h
series {
grid
parallel { ups1; ups2 }
kofn 2 of 3 { pdu1; pdu2; pdu3 }
standby cold { primary: pumpA; spare: pumpB; switch: 0.99 }
}
In this example only the grid states an mttr, so availability is computed with the other seven blocks counted as always available, and the figure reports that as an Availability partial gap. Give every block an mttr for a complete availability figure.
Blocks
block <id> ["Label"] key: value … (component, item and unit also work), with attributes in any order separated by spaces, commas or semicolons. The label falls back to the id. title "…" sets the title and mission 8760h (or mission time) the mission time; only the first of each is used. Durations take s, min, h (the default), d, w, mo or y, so 4000h, 18 months and 2.5 y all work.
| Key | Aliases | Meaning |
|---|---|---|
r | rel, reliability | Mission reliability, stated directly |
q | unreliability | 1 − r |
mtbf | mttf | Mean time between failures; R = e^(−t/MTBF) |
rate | lambda, λ | Failure rate, for example 2.5e-4 /h, 1.2/y or 85 fit |
mttr | repair | Mean time to repair. Turns on availability |
Every form is converted to a constant failure rate, which assumes an exponential life (the standard RBD assumption).
Arrangements
| Arrangement | Also written | Reliability |
|---|---|---|
series { a; b; c } | seq, sequence, chain, and, or bare braces | Product of the members |
parallel { a; b } | par, redundant, any, or | 1 − product of the members' unreliabilities |
kofn 2 of 3 { a; b; c } | k-of-n, koon, kn, vote, voting, mofn, m-of-n, majority; of, out, oo, from; kofn 2 { … } | Exact, even when members differ. The members you list set n; with no k, a majority (more than half) is required |
standby cold { primary: a; spare: b; switch: 0.99 } | backup, cold-standby, warm-standby, hot-standby | Spares used strictly in order. cold spares do not age, warm age at 10% of their rate, hot at the full rate, or set dormancy: 0.25. switch: is the changeover success probability |
Separators ;, , and new lines all delimit members. A name referenced but never declared becomes an assumed perfect block, drawn dashed. A file with blocks and no arrangement is treated as one long series.
What it computes
| Tile or line | Meaning |
|---|---|
| System reliability | At the mission time (default 8760 h, one year) |
| Unreliability | 1 − reliability |
| System MTTF | Integrated numerically. Shown as "System MTTF (lower bound)" with "≥" when the system is too reliable to decay within the integration horizon |
| Availability | Steady-state, when any block has mttr; otherwise "no mttr given" |
| Importance | Each block's Birnbaum importance and its share of system failure, ranked (up to eight rows) |
| Weakest link | A sentence of the form "Weakest link: Grid supply — R …, Birnbaum …, …% of system failure. Improving this one block moves the system number further than improving any other." |
| Redundancy check | Each redundant branch is deleted in turn; a branch worth less than 0.1% of system reliability is flagged as redundancy that buys almost nothing |
What it checks
| Finding | Level | Meaning |
|---|---|---|
| No quantities | Error | Every placed block is carried at R = 1, so the panel's 1.000000 is not a result |
| Assumed block | Error | The arrangement names an id no block line declares. It is drawn dashed and counted as a block that never fails |
| Unstated reliability | Error | A declared block with no r, q, mtbf or rate, carried at R = 1 |
| Repeated placement | Error | One block placed twice, which computes one physical component as two independent ones |
| Empty group | Error | A parallel, kofn or standby with no members, which computes as certain failure |
| Non-conforming value | Warning | A value outside its range, corrected: r: 150 is carried as certainty and r: -1 as impossibility |
| Unplaced block | Warning | Declared with numbers but never placed, so it is in no result |
| Block redeclared | Warning | The same id declared twice; the first wins |
| Attribute restated | Warning | Two statements about one block where only one survived, such as r: beside mtbf: |
| Singleton group | Warning | A redundant group with one member, computed as that member alone |
| k-of-n arity | Warning | The k or n written is not the one computed |
| Idle redundancy | Warning | A branch worth less than 0.1% of system reliability |
| Reliability underflow | Warning | System reliability is too small for the arithmetic to hold and reads as 0. Shorten the mission |
| Unreadable value | Gap | An attribute the engine could not use, such as a zero or negative duration or a negative rate. Reported, never treated as a perfect block |
| Assumed arrangement | Gap | No arrangement, so every block was chained in series in declaration order |
| Assumed mission, mission clamped | Gap | No usable mission, so 8760 h was used; or a mission above the engine's ceiling was cut down |
| Availability unstated, availability partial | Gap | No block gives a readable mttr, or only some do; blocks without one count as always available |
| MTTF lower bound | Gap | The system is too reliable to decay within the integration horizon |
| Line not read, size limit reached | Gap | Part of the document never reached the arithmetic. When a size limit was reached, the four tiles read "(withheld)" with "—" |
| Empty diagram | Gap | Nothing in the source was read as a block |
| No redundancy | Info | No redundant group anywhere: every block is a single point of failure. A fact about the design |
| AND group | Info | A kofn with k equal to n, which is a series in disguise |
| Weakest link | Info | The block whose improvement moves the system furthest |
Templates: Earth Observation Payload Chain, Potable Water Pumping Station, Radiotherapy Treatment Chain, Data-Centre Power Train, Fly-by-Wire Pitch Channel, Subsea Multiphase Boosting Station, GEO Ku-Band Payload, Hospital Medical Oxygen Supply, 25 kV Rail Traction Chain, Offshore Wind Turbine Drivetrain, Dual-Carrier WAN Path, Autonomous Vehicle Perception Chain, Municipal Water Treatment Works, and two availability models for cloud APIs.
Attack tree
Threat modelling with the attacker's cheapest path rolled up the tree.
title "Steal credentials"
goal G "Steal user credentials"
OR G1 "Phishing" parent G
AND G2 "Server compromise" parent G
leaf L1 "Send phishing email" parent G1 cost 1 skill low detect medium
leaf L2 "User clicks link" parent G1 cost 0 skill none detect low
leaf L3 "Exploit RCE" parent G2 cost 5 skill high detect medium
leaf L4 "Dump password DB" parent G2 cost 2 skill medium detect high
| Statement | What it does |
|---|---|
title "…" | Title |
goal ID "Text" | The attacker's goal, at the root. The tree is rooted at the first goal; a second goal is reported and not drawn |
AND ID "Text" parent P | A step that needs all of its children to succeed. The text is one word or quoted |
OR ID "Text" parent P | A step that needs any one of its children |
leaf ID "Text" parent P | An attacker action. May add cost N, skill none, low, medium or high, and detect low, medium or high |
Lines starting with # or // are comments, and keywords are case-insensitive. With no goal, the figure shows "Add a goal — goal G "Steal credentials"". Leaf cost, skill and detect appear as chips. Cost rolls up the tree: an AND adds its children's costs and an OR takes the cheapest, so the chip on the goal is the price of the cheapest way in. When a child has no cost, the chip says how many steps the number leaves out.
| Finding | Level | Meaning |
|---|---|---|
| Cost incomplete | Error | A gate's rolled-up cost left out a child with no cost, so the price shown is lower than the attack's |
| Node unreachable | Error | A node whose parent names nothing, or whose chain of parents does not lead to the goal. It and everything beneath it are not on the figure |
| Line not read | Error | A line that is not a statement (including a leaf with no parent clause), a second goal, or an id declared twice. With a repeated id, children attach to the second declaration and the first is drawn with nothing under it |
| Gate childless | Warning | An AND or OR with no children |
| No goal | Gap | No goal line, so there is no tree to draw |
| Tree result | Info | The tree's own result, stated |
Diagram Intelligence adds the number of attack scenarios, the cheapest attack and defender choke points (steps present in every attack scenario). On a very large tree the scenario enumeration is cut short and Intelligence says the scenarios and choke points are approximate. Templates include Steal user credentials, Cloud account takeover, Data exfiltration, Ransomware, Account Takeover, Data-Centre Break-in, Web App Compromise, IoT Device Hijack, Card-Not-Present Fraud and Water Treatment Dosing Attack. For software threat models, see also Software and architecture engines.
Automation, control and process engineering
Ladder logic (PLC)
IEC 61131-3 ladder diagrams, solved for one scan exactly as a controller runs them.
title "Motor starter"
state: Start_PB, Stop_PB, Overload_OK, Motor_Run, Eye_Blocked
rung "Seal-in"
branch
xic Start_PB
xic Motor_Run
xic Stop_PB
xic Overload_OK
ote Motor_Run
rung "Jam watchdog"
xic Motor_Run
xic Eye_Blocked
ton T_Jam preset: 6 accum: 8 unit: s
rung "Jam alarm"
--| |--T_Jam----( )--Jam_Alarm
This program solves as three rungs over ten tags, all three true in the declared state, with no findings. Note the rung "Jam alarm" line: an instruction line written while a rung is open joins that rung, so without it the one-line rung would be drawn in series at the end of "Jam watchdog". A one-line rung stands on its own only when no rung block is open, for example at the top of the program.
Statements
| Statement | Also accepted | What it does |
|---|---|---|
title "…" | Title. The first wins | |
state: A, B=0, C | inputs:, input: | The tags that are true. A bare tag is true; Tag = 0 is false. Values accept 1/0, on/off, true/false, closed/open, high/low, yes/no and set/clear. Also read as true: t, y, hi, up, made, live, energised. Also read as false: f, n, lo, down, reset, cleared, deenergised. Any other value, and any non-zero number, reads as true, so write deenergised as one word: de-energised with a hyphen reads as true. The list may continue on following lines until a rung, a title or an instruction line |
rung | rung "comment", rung 3 "comment" | Opens a rung. Following instruction lines join it until the next rung, title or state line |
branch | parallel, or | Opens parallel legs (OR). Each line indented under it is one leg; branches can nest |
| An instruction line with no rung open | Becomes a one-line rung of its own |
Instructions
| ASCII art | Keyword | Meaning |
|---|---|---|
--] [--Tag (or the pipe form shown below) | xic Tag; also no, noc, contact, examineon, closed | Normally open contact: true when Tag is true |
--]/[--Tag (or the pipe form shown below) | xio Tag; also nc, ncc, notcontact, examineoff, inverted | Normally closed contact: true when Tag is false |
--( )--Tag | ote Tag; also coil, out, output, energise, energize | Output coil, written every scan |
--(S)--Tag or --(L)--Tag | set Tag; also otl, latch, seal | Latch: writes 1, never 0 |
--(R)--Tag or --(U)--Tag | reset Tag; also otu, unlatch, rst | Unlatch: writes 0, never 1 |
ton T preset: 5 accum: 3; also timer | On-delay timer | |
tof T preset: 5 accum: 3 | Off-delay timer | |
tp T preset: 5 accum: 3; also pulse | Pulse timer | |
ctu C preset: 500 accum: 412; also counter | Count-up counter | |
ctd C preset: 8 accum: 0 | Count-down counter |
The contacts can also be drawn with pipes, which is how most ladder printouts look:
--| |--Start_PB # normally open contact, same as: xic Start_PB
--|/|--Jam # normally closed contact, same as: xio Jam
--( )--Motor # output coil, same as: ote Motor
--(S)--Alarm # latch, same as: set Alarm
--(R)--Alarm # unlatch, same as: reset Alarm
preset: also accepts pre:, pt: and sp:; accum: accepts acc:, et:, cv: and count:. Two bare numbers after the tag are read as preset then accumulated (ton T_Jam 6 8). A trailing s, ms or min is kept as the display unit. The tag always follows its symbol, and may be quoted when it contains spaces. A whole rung fits on one line: --| |--Start_PB----|/|--Jam----( )--Motor.
A timer or counter named T_Jam provides T_Jam.EN (or .CU and .CD), T_Jam.TT and T_Jam.DN, and T_Jam on its own means the done bit. A/B is read as A.B. Tag names are case-insensitive; the first spelling is the one drawn.
How it solves
Tags start from the declared state; everything else is false. Each rung is evaluated left to right: series is AND, parallel legs are OR, a normally closed contact inverts, and an output passes power through, so two coils in series both fire. ote writes every scan; a latch survives its own rung going false; when a set and a reset are both powered in one scan, the last executed wins. Timers and counters resolve their done bits from the declared accumulated value against the preset (IEC rules), and time does not advance during the scan. A coil written on an earlier rung is visible to a later one; to show a seal-in holding, declare the coil in state as it was at the end of the previous scan. Energised rails, contacts and coils are highlighted.
What it flags
| Finding | Level | Meaning |
|---|---|---|
| Duplicate destination | Error | A tag written by more than one output, by an output and a latch, or by two timer or counter blocks. The last rung wins and the earlier one is dead code |
| Read but never written | Error | A tag examined by a contact that no output writes and state does not declare: the typo that always reads zero |
| Rung with no output | Warning | Logic solved and thrown away, usually because a coil was deleted |
| Program truncated, no rung | Gap | A size limit was reached, or no rung was read |
| Never energised | Shown on the strip | Outputs no instruction drove true in the declared state. This is a result for that input state, not a defect |
When there are none, the strip says so: no duplicate destinations, no unwritten tags, every rung drives an output. Templates: Motor Start/Stop Seal-In, Signalled Junction Sequence, Conveyor Jam Watchdog, Tank Fill on Level Switches, Two-Hand Press Anti-Tie-Down, Roller Door Open/Close Interlock, Packaging Line Fill and Cap, Duplex Pump Duty Alternation, Lift Hall Call and Door Dwell, and Batch Mixer Charge and Soak.
GRAFCET / SFC
IEC 60848 GRAFCET and IEC 61131-3 sequential function charts, checked against the rules every hand-drawn chart breaks.
title "Bottling line — filler cycle"
step 1 "Idle" initial
action N "Conveyor stopped"
step 2 "Index bottle"
N "Conveyor forward"
S "Gate solenoid"
step 3 "Fill"
N "Fill valve open"
L 8s "Nitrogen purge"
D 5s "Alarm horn" if level_low
step 4 "Cap"
transition t1 : "start . bottle_present"
transition t2 : "bottle_at_filler"
transition t3 : "level_high + timeout"
transition t4 : "cap_done"
1 -> t1 -> 2 -> t2 -> 3 -> t3 -> 4
4 -> t4 -> 1
Statements
| Statement | What it does |
|---|---|
step 7 "Label" | A numbered step. initial (or init) anywhere on the line marks it initial; final (or end) marks a deliberate stopping point. initial step 1 "Idle" also works |
action N "Text" | An action under the step above. The bare N "Text" and action "Text" (defaults to N) also work |
D 5s "Text", L 8s "Text" | Delayed and time-limited actions take a time |
… if condition | A condition on any action, drawn beside it |
transition t3 : "receptivity" | A transition's condition. The colon and quotes are optional, and t3 : level_high works |
A -> B -> C | A link chain. →, => and --> are the same arrow |
3 -> t4, t5 | One step to several transitions: alternative (OR) divergence, single bar |
t4, t5 -> 8 | Alternative convergence, single bar |
t2 -> 4, 6 | One transition to several steps: simultaneous (AND) divergence, double bar |
5, 7 -> t8 | Simultaneous convergence, double bar |
| Qualifier | Meaning |
|---|---|
| N | Continuous, while the step is active |
| S | Set (stored) |
| R | Reset |
| D | Delayed, with a time |
| L | Time-limited, with a time |
| P | Pulse |
| C | Conditional |
In links, a step is 3, s3 or step 3; a transition is t3, tr3 or transition 3. Nodes referenced but not declared are created, so you can write the spine first. Receptivities pass IEC notation through: . is AND, + is OR and /x is NOT. A transition with no receptivity is drawn =1. A link line may be prefixed with or or alternative, or and, simultaneous or parallel; the engine checks that word against the structure. Links that run back up the chart are routed down the left rail with an arrowhead.
What it checks
| Finding | Level | Meaning |
|---|---|---|
| Alternation break | Error | A step linked straight to a step, or a transition to a transition. Each pair is named and drawn in the warning colour |
| No initial step, or several | Error | Checked per connected sequence |
| Unreachable step | Error | No path from its sequence's initial step |
| AND unbalanced | Error | A simultaneous divergence not closed by a convergence of the same width |
| Unopened convergence | Error | A simultaneous convergence with no matching divergence |
| Duplicate step | Error | A step number declared twice. The first declaration is kept |
| Dangling transition | Error | A transition not connected on both sides |
| Line not read, no links | Error | A line the engine could not read, or a chart with steps but no links |
| Dead-end step | Warning | No outgoing transition and not marked final |
| Unconditional transition | Warning | A transition with no receptivity, drawn =1 |
| Keyword mismatch | Warning | An or or and prefix that contradicts the chart |
| Step undeclared | Warning | A step that appears only in links; actions written under a mistyped step line attach to the step above |
| Chart truncated | Gap | A size limit was reached, so the chart is not called well formed |
| Chart shape | Info | The chart's own structure, stated |
Templates: CIP Sequence (10 000 L Fermenter), Rotary Bottling Filler, Lift Car Door Interlock, CNC Automatic Tool Change, Batch Reactor Heat-Hold-Cool, Car Park Entry Barrier, Robot Pick-and-Place Cell, Rollover Car Wash Gantry, Signalised T-Junction Stages, Commercial Dishwasher Cycle and Cleanroom Material Airlock.
P&ID (chemical engineering)
Process and instrumentation diagrams placed on a grid.
title "Continuous distillation"
eq tank T1 "Feed tank" at (1,1)
eq pump P1 "Feed pump" at (3,1)
eq column COL1 "Distillation" at (5,1)
eq exchanger E1 "Reboiler" at (7,3)
eq tank T2 "Bottoms" at (5,4)
instrument TI 101 at (6,0.2)
instrument LC 201 at (6,1.8)
instrument PSHH 12-101 at (3,0.2)
line T1 P1 stream "feed"
line P1 COL1 stream "feed (pumped)"
line COL1 T2 stream "bottoms"
line COL1 E1 stream "reboil vapor"
This layout draws with no notices. Put the reboiler at (5,3), directly between the column and the bottoms tank, and the figure reports "The bottoms line is drawn through E1; it does not connect to it."; put a balloon on the column's own coordinates and it reports "Balloon TI 101 is drawn on top of COL1 — both are on the figure, one over the other."
| Statement | What it does |
|---|---|
eq KIND ID ["Label"] at (x,y) | A piece of equipment. The label is optional; the id is drawn in bold under the symbol with the label beneath it. Coordinates are grid cells and may be decimal or negative |
instrument TAG NUMBER at (x,y) | An ISA-5.1-style balloon. The tag is a letter followed by up to five letters or digits (FT, TI, LC, PSHH, PALL, LSHH, PDIT); the loop number may carry suffixes and prefixes such as 101A or 12-101 |
line FROM TO [stream "label"] | A process line between two pieces of equipment, with an optional stream label |
title … | Title |
| Equipment kind | Drawn as |
|---|---|
tank | Round outline |
vessel | Vessel with domed ends |
column | Tall column with trays |
exchanger | Shell with a coil |
pump | Circle with a discharge triangle |
compressor | Trapezoid |
reactor | Box marked R |
separator | Horizontal drum |
filter | Box with dashed media lines |
valve | Bow-tie valve symbol |
| Any other word | Plain square |
Lines starting with # or // are comments. Equipment kinds are matched without regard to case. The notice band under the drawing lists, up to six at a time (then "…and N more."), anything the engine could not draw cleanly.
| Finding | Level | Notice text or meaning |
|---|---|---|
| Line not read | Error | "Line N, "…", is not a declaration this engine reads — nothing on the figure comes from it." |
| Endpoint unknown | Error | "Line N routes A → B, but B names no equipment — that stream is not drawn." |
| Content clipped | Error | "This drawing needs Npx of width and was given Mpx — content past the right edge is not on the figure." Bring the far-right coordinates in |
| Pipe crosses equipment | Warning | "The … line is drawn through …; it does not connect to it." A process line that had to be drawn through unrelated equipment |
| Balloon overlaps | Warning | An instrument balloon on top of equipment ("…is drawn on top of…"), over a tag block ("…covers the tag block of…"), over another balloon ("…overlap each other.") or on a line's elbow ("…sits on the elbow of…") |
| No equipment | Gap | Nothing was declared with eq |
| Result | Info | The drawing's own counts, stated |
Templates: Water Treatment Plant, Brewhouse Wort Line, Food Waste Anaerobic Digester, Continuous distillation, CSTR with cooling and Shell-and-tube heat exchanger.
Related engines documented on other pages
The Studio library's Flow systems and Risk & reliability groups also hold engines that are documented in full elsewhere. In Flow systems: Data flow diagram and Event storming (Software and architecture engines); User story map, Business model canvas, Customer journey map, Decision matrix (weighted / Pugh), Gantt & critical path and Roadmap (Business, strategy and planning engines). In Risk & reliability: Decision tree and Risk matrix (Business, strategy and planning engines). Use the Risk matrix for a scored likelihood × impact register and heat map; use a bowtie or fault tree on this page when you need the barriers or the failure logic computed.
Two schedule engines sit closest to this family:
| Engine | Use it for | Reference |
|---|---|---|
| Gantt & critical path | Schedules computed from durations, all four precedence relationships with lead and lag, a working calendar, resources and deadlines, with critical path, float and conflicts flagged. view network draws the same schedule as a precedence network | /docs/engines/gantt |
| PERT / CPM network | A finish-to-start network with ES, EF, LS, LF and slack in every node and the critical path highlighted. task A "Design" duration 5, task B "Build" duration 10 after A, milestone M1 "Launch" after D, and unit days or unit hours to name the unit (with no unit line, durations are shown without one). In the library it sits under Engineering & physical | /docs/engines/pert |
Choosing between close cousins
| Question | Use | Rather than |
|---|---|---|
| Where does the time go in an end-to-end process, and which step cannot meet demand? | Value stream map | A swimlane, which shows handoffs but computes no times |
| Is our board's flow getting better or worse over weeks? | Flow metrics (CFD) | A Kanban board, which is a snapshot |
| How many servers or staff does each station need? | Queueing network | Diagram Intelligence's flow arithmetic, which compares shapes with 16 test arrivals and is not for capacity planning |
| How far do people walk, and what does a relayout save? | Spaghetti diagram | A floor plan with hand-drawn lines |
| What is in and out of scope for an improvement project? | SIPOC | A process map, which has no requirements |
| Is this process stable, and is it capable? | Control chart (SPC) | A run chart in a charting engine, whose limits would be typed by hand |
| Which few causes deserve attention first? | Pareto chart | A bar chart, which does not compute the vital few |
| What might be causing this problem? | Fishbone | A mind map |
| How likely is a failure and which combinations cause it? | Fault tree | A bowtie, which reasons in frequencies through barriers |
| Which barriers matter, and what is left after them? | Bowtie | A fault tree, which has no barriers |
| How reliable and available is the whole system? | Reliability block diagram | A fault tree of the same system, which answers the failure question rather than the success one |
| Does this PLC logic do what I think in this input state? | Ladder logic | GRAFCET, which describes sequence rather than scan logic |
| Is this machine sequence well formed? | GRAFCET / SFC | A state machine or flowchart, which does not check IEC alternation |
| A process to the BPMN 2.0 standard, with simulation | The BPMN studio | A swimlane |
Limits at a glance
These limits apply per figure. Past a limit, the engine keeps what it read, says what it did not, and withholds whole-figure verdicts.
| Engine | Limits |
|---|---|
| Value stream map | 60 steps (processes plus waits and inventories), 10 information flows, 6 extra data-box keys per step, 10 rows per data box, labels of 64 characters, 4,000 lines |
| Flow metrics (CFD) | 8 stages, 400 data rows, 8 WIP limits, stage and row labels of 48 characters; up to 6 warnings and 5 notes shown |
| Queueing network | 14 stations, 160 routes, 32 arrival streams, 512 servers and capacity 512 per station, names of 44 characters, 5,000 lines |
| Spaghetti diagram | 200 stations, 60 zones, 24 paths, 240 stops on one path, 600 legs, 2 scenarios, 4,000 lines |
| SIPOC | 24 items per column, 40 process steps, 120 requirements (3 per item), 5 metrics, 4,000 lines |
| Control chart (SPC) | 400 points, subgroups of up to 25, 256 numbers on one line |
| Pareto chart | 200 categories read, 2 to 30 bars drawn (15 by default), lines of 2,000 characters |
| Design structure matrix | 64 elements, 3,000 dependencies, 4,000 lines |
| Fault tree | 200 gates, 64 distinct basic events reachable from the top (beyond that the tree is not analysed), 12 inputs per gate, 2,000 cut sets; 10 cut sets and 8 importance rows shown; mission time up to about 1,000 years; 4,000 lines |
| Bowtie | 12 threats, 12 consequences, 6 barriers per path, 4 escalation factors per barrier, 4 controls per escalation, 4,000 lines |
| Reliability block diagram | 120 blocks, 32 members per group, nesting 12 deep, 4,000 lines |
| Ladder logic | 40 rungs, 24 elements per rung, 16 per line, 8 legs per branch, branches 5 deep, 40 tags in state, 4,000 lines |
| GRAFCET / SFC | 60 steps, 60 transitions, 240 links, 8 actions per step, 4,000 lines |
| P&ID | Up to 6 notices listed at a time |
| Kanban | Up to 6 notices listed at a time |
| Swimlane | Lines of 2,000 characters; up to 3 findings printed on the figure |
| Fishbone | The canvas widens by up to 800 px before a cause is shortened; up to 5 notices listed at a time |
| Service Blueprint, Attack tree | No engine-specific count limits. Long labels are wrapped or shortened and reported |
Every engine on this page also has a source-size budget in the Studio: 60,000 bytes (about 58.6 KB) of source, or 150,000 bytes (about 146.5 KB) for the control chart and the CFD, whose sources grow one row per observation. Past it the figure is not drawn and you see "Source is … — past the … safe-rendering budget for …", with three options: split the work into smaller figures, render it on the server with the render API, or trim the source. See Troubleshooting and FAQ.
Tips
- Start from a template. Every engine here has a set of real-world templates. Open one, then replace its numbers with yours: the structure is already right.
- Write the inputs, never the totals. If you find yourself wanting to type a total, a limit, a probability or a verdict, that is the number the engine computes. Type the facts it is computed from.
- Give units every time. Write
8m,12/hand4000hrather than bare numbers. The queueing network reports every unitless value, and in the value stream map a bare number is seconds. - Mark the waiting. In a CFD,
*on waiting stages is what makes flow efficiency possible. In a value stream map,waitandinventorylines carry the non-value-added time. - Use the before-and-after forms. The spaghetti
scenarioand the Paretocomparecolumn turn one figure into an argument with the difference computed, and the queueingtargetturns the verdict into a server count you can act on. - State the takt. Without
takt, ordemandwithavailable, a value stream map cannot say which step is over takt. - Declare the previous scan. In ladder logic, a seal-in only holds if the coil is in
stateas it was at the end of the last scan. - Mark the deliberate ends. In GRAFCET, mark terminal steps
finalso the dead-end check does not report them. - State what the engine would otherwise assume. A queueing network with no
targetline, a fault tree with rates but nomissionline, any RBD with nomissionline, and a control chart shorter than 15 points with all eight rules on each carry a Gap in Document status, because a number was chosen for you. Writetarget 85%,mission 8760horrules: 1,5and the gap clears. - Read the notes before you present. A note such as "1 threat likelihood assumed 0.1" on a bowtie, or "Timings assumed" in Diagram Intelligence, is the line a reviewer will ask about.
- Name a version before a what-if. Open the diagram timeline (Version history…,
⇧⌘H) to name the current version, then change the inputs. See Version history and undo. - Keep one figure per engine you try. Picking a different engine replaces the figure's source with that engine's starter, so start a New figure (
⌥⌘N) for each comparison and keep both.
Limits and known constraints
- The Studio computes; it does not animate. These engines draw their results into a static figure. Animated token flow is in Weave and the BPMN studio.
- The queueing network is a steady-state, open-network model. It treats arrivals as Poisson unless a station states a
cva, solves long-run averages, and uses the Allen–Cunneen approximation whenever variability is stated on a multi-server station or on arrivals. A finite-capacity station is always solved as M/M/c/K, ignoring anycv. A station at exactly ρ = 100% counts as unstable. It does not model priorities, schedules that change over the day, or closed networks, and at most 14 stations are solved. - Reliability block diagrams assume constant failure rates (an exponential life), so they do not substitute for a Weibull analysis of wear-out. Repair is used only for steady-state availability.
- Bowtie barriers are treated as independent. Common-cause failure is not modelled, and each consequence is credited the full top-event frequency. Both are reported when they matter.
- Fault trees must be coherent for cut sets to be meaningful. XOR, NOT, NAND and NOR are accepted but computed as OR and reported as errors. A tree with more than 64 distinct basic events is not analysed at all, and a very tangled tree that exhausts the exact method falls back to a labelled upper bound.
- Ladder logic solves one scan. Timers and counters do not advance; their state comes from the
accumyou declare. - The CFD's cycle time is approximate, from Little's Law over the window, and assumes a reasonably stable system. The value stream map converts count-only inventories to time only when takt is known.
- P&ID is a drawing aid, not a process simulator. It has one generic valve symbol (gate, ball, check and control valves are not distinguished), lines are routed automatically between equipment, and you place items by grid coordinates.
- Swimlane, Kanban, Fishbone, Attack tree, P&ID and Service Blueprint accept comments only on lines of their own (and Service Blueprint only with
#). - Direct click-to-edit tools are limited here. Click a label on the figure to rename it (Enter saves, Esc cancels); the new text is written straight into your source. When the old label cannot be located in the source safely, the rename is handed to AI instead, and any other change goes through Ask the flowss Studio Agent… in the same popover. Both of those need AI on your plan. Everything else is edited in the code. See Data, timeline, TikZ and the diagram tools.
Troubleshooting
| What you see | What it means | What to do |
|---|---|---|
| A syntax hint in place of the figure | The engine found nothing it could draw | Compare your lines with the examples on this page, or start from a template. The table below lists each engine's hint |
| "…is empty because the document was not read to the end." | A size limit was reached before anything drawable | Shorten the document or split it; see Limits at a glance |
| A tile labelled "(withheld)" or a value shown with "≥" | Part of the document was not read, so ratios and verdicts are withheld and sums are floors | Fix the lines named in the notes, or reduce the size |
| A line reported as not read, or "matched no directive" | A misspelt keyword or a note written without # | Correct the keyword or comment the line out |
| Flow efficiency "n/a" in a CFD | No stage is marked as waiting | Add * after the waiting stages' names |
| "Unknown commit stage …" in a CFD | commit names no stage | Use the exact stage name from stages: |
| "Needs at least two subgroups before limits can be estimated." | Too little SPC data | Add more subgroups or readings |
| "Unstable — … its queue grows without bound." | A queueing station is at or above 100% utilisation | Add servers, shorten the service time or reduce arrivals. The verdict names how many servers would meet the target |
| "Unsolvable — the traffic equations are singular…" | A routing loop with no exit | Route some probability from one station in the loop to exit |
| A queueing verdict of "ρ = 0%" with a No arrivals warning | The network has stations but no arrivals line, so nothing enters it | Add arrivals NAME 12/h (or whatever the real rate is) |
| A dashed station in a spaghetti diagram | A path names a station you never placed | Add a station NAME at X,Y line, or fix the spelling |
| "Cyclic gate reference: … — a fault tree must be acyclic." | A gate refers back to itself through its inputs | Remove the circular reference |
| "… basic events — exact analysis is capped at 64." | More than 64 distinct basic events are reachable from the top | Split the tree into sub-trees, or model a sub-system as one undeveloped event with its own probability |
| "The tree has no basic events to compute with." | Every branch ends at a gate | Add event lines for the leaves |
| "Top event probability (bound)" | The exact method ran out of room on a very tangled tree | Reduce repeated events or tree size, or accept the labelled upper bound |
| A queueing value reported as coerced with "ρ is COMPUTED…" or "a SQUARED coefficient of variation…" | You stated rho, utilisation or scv in a station block | Remove it. State servers and service time, and write cv unsquared |
| An RBD reading 1.000000 with "no quantities" | No placed block states a reliability | Give each block r, q, mtbf or rate |
| An attack-tree chip lower than you expected | A child has no cost, so the roll-up leaves it out | Add cost to every leaf; the chip says how many steps it is missing |
| A bowtie finding "assumed …" | A likelihood, severity or effectiveness was missing and a default was used | Give the missing value |
| A dashed block in an RBD | The arrangement names a block you never declared, assumed perfect | Declare the block with r, mtbf or rate |
| A Kanban notice that cards "are drawn in" another column | A column line above them could not be read | Fix the column line; quote names with spaces and use a whole-number wip |
| A swimlane note that an arrow "names a step this diagram never declares — not drawn" | The arrow uses an id with no node line | Use the node's id, not its label |
| A P&ID notice "…names no equipment — that stream is not drawn." | A line endpoint is not an equipment id | Use the id from the eq line |
| A GRAFCET link drawn in the warning colour | Steps and transitions do not alternate on that link | Insert the missing transition or step |
| Ladder "read but never written" for a tag you expected to be true | The tag is not in state and no output writes it | Add it to state, or fix the spelling |
| A seal-in rung that does not hold | Ladder solves one scan; the coil was false at the start of it | Declare the coil in state as it was at the end of the previous scan |
| A SIPOC "orphan requirement" | A requirement names an item no column holds | Match the item's wording (case and plurals are forgiven) or add the item |
| A control chart "directive misread" | A first word one letter from a keyword, such as spek, was charted as data | Correct the keyword; the stray number is removed from the run |
| "Source is … — past the … safe-rendering budget for …" | The source is over the Studio's size budget for this engine (60,000 bytes, or 150,000 for SPC and CFD) | Split the work across several figures, trim the source, or render it on the server with the render API |
| A value stream line reported as "matched no directive" although the step is on the map | The step was written as a bare NAME { … }, or its data box spans several lines | Start the line with process and keep the data box on one line |
| A Document status gap such as "assumed target", "assumed mission" or "rule window unreachable" | The engine used a value you did not state, or the run is too short for some Nelson rules | State it: target 85%, mission 8760h, or a rules: list that fits the run |
| A DSM element named like a keyword, such as "elemnts: Body, Chassis" | A mistyped declaration line became one element | Correct the keyword; the "declaration misread" warning names the line |
Empty-figure hints by engine
| Engine | Hint shown when nothing could be drawn |
|---|---|
| Value stream map | "Describe the stream, top to bottom" |
| Flow metrics (CFD) | "Cumulative flow diagram", with the expected row format |
| Queueing network | "Describe the network — arrivals 12/h" |
| Spaghetti diagram | "Place the floor, then walk it" |
| SIPOC | "Scope the process — one column per line" |
| Control chart (SPC) | "Add measurements — subgroup 500.1 499.8 500.4 500.0" |
| Pareto chart | "Add one category per line — "Late delivery" 412", or "Nothing here could be charted, and it is not because the document is empty." when every line failed to read |
| Design structure matrix | "Design structure matrix — declare elements, then their inputs" |
| Fault tree | "Describe the tree — top "Cooling lost" = AND(pump_fail, backup_fail)" |
| Bowtie | "Describe the risk — threats on the left, consequences on the right" |
| Reliability block diagram | "Declare blocks then arrange them — block ups1 "UPS A" r: 0.98" |
| Ladder logic | "Wire a rung between the rails, then say which tags are true" |
| GRAFCET / SFC | "Chart the sequence — steps, transitions, and the links between them" |
| Swimlane process | "Add a lane and some nodes — lane "Customer", node A "Open" in Customer" |
| Kanban board | "Add a column — column "To do" / card "Task"" |
| Attack tree | "Add a goal — goal G "Steal credentials"" |
Fishbone, Service Blueprint and P&ID have no hint: an empty fishbone draws the four default ribs around a "Problem" head, an empty blueprint draws five empty lanes, and an empty P&ID draws an empty grid.
Related pages
- Flow-systems analysis in Studio
- Choosing an engine
- The full engine catalogue
- Business, strategy and planning engines
- Software and architecture engines
- Charts and data-visualisation engines
- The Studio editor
- Starting from a template
- Importing and converting
- BPMN and Weave
- The Flow layer
- Exporting your work
- Embedding and the render API
- Use cases by role
